nerdexam
CompTIA

CAS-002 · Question #577

A manufacturing company is having issues with unauthorized access and modification of the controls operating the production equipment. A communication requirement is to allow the free flow of data…

The correct answer is C. Implement an AAA solution. An AAA (Authentication, Authorization, and Accounting) solution directly addresses unauthorized access and modification of industrial controls by enforcing who can log in, what they are permitted to do, and maintaining an audit trail.

Technical Integration of Enterprise Components

Question

A manufacturing company is having issues with unauthorized access and modification of the controls operating the production equipment. A communication requirement is to allow the free flow of data between all network segments at the site. Which of the following BEST remediates the issue?

Options

  • AImplement SCADA security measures.
  • BImplement NIPS to prevent the unauthorized activity.
  • CImplement an AAA solution.
  • DImplement a firewall to restrict access to only a single management station.

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    83% (30)
  • D
    6% (2)

Why each option

An AAA (Authentication, Authorization, and Accounting) solution directly addresses unauthorized access and modification of industrial controls by enforcing who can log in, what they are permitted to do, and maintaining an audit trail.

AImplement SCADA security measures.

SCADA security measures are a broad category of controls relevant to industrial environments, but the question asks for the best single remediation for access and modification control, where AAA is more precise and direct.

BImplement NIPS to prevent the unauthorized activity.

A NIPS (Network Intrusion Prevention System) can block known attack patterns in transit but does not authenticate or authorize users, meaning a legitimate but unauthorized insider could still modify controls.

CImplement an AAA solution.Correct

AAA enforces Authentication to verify identity before granting access, Authorization to restrict which users can modify production equipment controls, and Accounting to log all actions for auditing and forensics. This directly remediates both unauthorized access and unauthorized modification without restricting the free flow of data between network segments, satisfying the stated communication requirement.

DImplement a firewall to restrict access to only a single management station.

Restricting access to a single management station via firewall would contradict the explicit requirement to allow the free flow of data between all network segments at the site.

Concept tested: AAA controls for industrial control system access management

Source: https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/13838-authentication.html

Topics

#SCADA security#ICS#AAA#access control

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice