CAS-001 · Question #425
A security administrator is investigating the compromise of a SCADA network that is not physically connected to any other network. Which of the following is the MOST likely cause of the compromise?
The correct answer is C. Infected USB device. An air-gapped SCADA network cannot be reached over a network, so the most realistic attack vector for introducing malware is through infected removable media such as a USB drive.
Question
A security administrator is investigating the compromise of a SCADA network that is not physically connected to any other network. Which of the following is the MOST likely cause of the compromise?
Options
- AOutdated antivirus definitions
- BInsecure wireless
- CInfected USB device
- DSQL injection
How the community answered
(58 responses)- A2% (1)
- B5% (3)
- C86% (50)
- D7% (4)
Why each option
An air-gapped SCADA network cannot be reached over a network, so the most realistic attack vector for introducing malware is through infected removable media such as a USB drive.
Outdated antivirus definitions could allow malware to run undetected once present, but they are not a vector for initial compromise of an air-gapped network.
Insecure wireless would imply a wireless network connection exists, which contradicts the premise that the network is not physically connected to any other network.
Because the SCADA network is physically isolated with no external network connections, an attacker must introduce malware via a physical medium. Infected USB devices are the classic and documented vector for air-gap compromise - most notably demonstrated by Stuxnet - where a drive used by maintenance personnel or contractors carries malware that executes when plugged into a system on the isolated network.
SQL injection is a network-based attack targeting web application database interactions, which requires network connectivity that does not exist on an air-gapped network.
Concept tested: Air-gap compromise via infected removable media
Source: https://www.cisa.gov/sites/default/files/publications/ICS-CERT_USB_Security_Fact_Sheet.pdf
Topics
Community Discussion
No community discussion yet for this question.