nerdexam
CompTIA

CAS-002 · Question #46

A company recently experienced a malware outbreak. It was caused by a vendor using an approved non-company device on the company's corporate network that impacted manufacturing lines, causing a week…

The correct answer is D. Deploy an ACL that restricts access from the corporate network to the manufacturing SCADA. The root cause of the incident was a vendor device on the corporate network being able to reach and infect manufacturing SCADA systems. Deploying an ACL (Access Control List) that restricts traffic from the corporate network to the manufacturing SCADA network creates a network…

Technical Integration of Enterprise Components

Question

A company recently experienced a malware outbreak. It was caused by a vendor using an approved non-company device on the company's corporate network that impacted manufacturing lines, causing a week of downtime to recover from the attack. Which of the following reduces this threat and minimizes potential impact on the manufacturing lines?

Options

  • ADisable remote access capabilities on manufacturing SCADA systems.
  • BRequire a NIPS for all communications to and from manufacturing SCADA systems.
  • CAdd anti-virus and client firewall capabilities to the manufacturing SCADA systems.
  • DDeploy an ACL that restricts access from the corporate network to the manufacturing SCADA

How the community answered

(41 responses)
  • A
    7% (3)
  • B
    29% (12)
  • C
    12% (5)
  • D
    51% (21)

Explanation

The root cause of the incident was a vendor device on the corporate network being able to reach and infect manufacturing SCADA systems. Deploying an ACL (Access Control List) that restricts traffic from the corporate network to the manufacturing SCADA network creates a network segmentation boundary, preventing unauthorized or compromised devices on the corporate network from communicating with critical OT (Operational Technology) systems. Option A (disabling remote access) does not prevent lateral movement from devices already on the corporate network. Option B (NIPS) can detect but does not block traffic by default and doesn't minimize impact. Option C (AV on SCADA systems) is often impractical because SCADA/ICS systems are frequently incompatible with traditional endpoint security software and patching, and does not address the network-level exposure.

Topics

#SCADA#network segmentation#ACL#ICS security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice