nerdexam
CompTIA

CAS-001 · Question #425

A security administrator is investigating the compromise of a SCADA network that is not physically connected to any other network. Which of the following is the MOST likely cause of the compromise?

The correct answer is C. Infected USB device. An air-gapped SCADA network cannot be reached over a network, so the most realistic attack vector for introducing malware is through infected removable media such as a USB drive.

Technical Integration of Enterprise Components

Question

A security administrator is investigating the compromise of a SCADA network that is not physically connected to any other network. Which of the following is the MOST likely cause of the compromise?

Options

  • AOutdated antivirus definitions
  • BInsecure wireless
  • CInfected USB device
  • DSQL injection

How the community answered

(58 responses)
  • A
    2% (1)
  • B
    5% (3)
  • C
    86% (50)
  • D
    7% (4)

Why each option

An air-gapped SCADA network cannot be reached over a network, so the most realistic attack vector for introducing malware is through infected removable media such as a USB drive.

AOutdated antivirus definitions

Outdated antivirus definitions could allow malware to run undetected once present, but they are not a vector for initial compromise of an air-gapped network.

BInsecure wireless

Insecure wireless would imply a wireless network connection exists, which contradicts the premise that the network is not physically connected to any other network.

CInfected USB deviceCorrect

Because the SCADA network is physically isolated with no external network connections, an attacker must introduce malware via a physical medium. Infected USB devices are the classic and documented vector for air-gap compromise - most notably demonstrated by Stuxnet - where a drive used by maintenance personnel or contractors carries malware that executes when plugged into a system on the isolated network.

DSQL injection

SQL injection is a network-based attack targeting web application database interactions, which requires network connectivity that does not exist on an air-gapped network.

Concept tested: Air-gap compromise via infected removable media

Source: https://www.cisa.gov/sites/default/files/publications/ICS-CERT_USB_Security_Fact_Sheet.pdf

Topics

#SCADA security#air gap#USB threat vector#ICS compromise

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice