nerdexam
CompTIA

CAS-002 · Question #817

The latest independent research shows that cyber attacks involving SCADA systems grew an average of 15% per year in each of the last four years, but that this year's growth has slowed to around 7%…

The correct answer is B. Spending on SCADA security controls should stay steady; application control spending should. Security spending should be adjusted based on attack trend data - stable or declining threats warrant steady or reduced spending, while exponentially growing threats require increased investment.

Research and Analysis

Question

The latest independent research shows that cyber attacks involving SCADA systems grew an average of 15% per year in each of the last four years, but that this year's growth has slowed to around 7%. Over the same time period, the number of attacks against applications has decreased or stayed flat each year. At the start of the measure period, the incidence of PC boot loader or BIOS based attacks was negligible. Starting two years ago, the growth in the number of PC boot loader attacks has grown exponentially. Analysis of these trends would seem to suggest which of the following strategies should be employed?

Options

  • ASpending on SCADA protections should stay steady; application control spending should
  • BSpending on SCADA security controls should stay steady; application control spending should
  • CSpending all controls should increase by 15% to start; spending on application controls should be
  • DSpending on SCADA security controls should increase by 15%; application control spending

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    55% (16)
  • C
    14% (4)
  • D
    24% (7)

Why each option

Security spending should be adjusted based on attack trend data - stable or declining threats warrant steady or reduced spending, while exponentially growing threats require increased investment.

ASpending on SCADA protections should stay steady; application control spending should

This option incorrectly handles the bootloader spending allocation by not prioritizing the exponentially growing bootloader and BIOS threat with a sufficient budget increase.

BSpending on SCADA security controls should stay steady; application control spending shouldCorrect

SCADA attack growth has slowed significantly from 15% to 7%, suggesting existing controls are effective and spending should remain steady rather than increase. Application attack counts are flat or declining, indicating current controls are sufficient and spending could potentially be reduced. The exponential growth of PC bootloader and BIOS attacks represents the most rapidly emerging threat and warrants the greatest increase in security investment.

CSpending all controls should increase by 15% to start; spending on application controls should be

A blanket 15% increase across all controls ignores the trend data showing SCADA growth has slowed and application attacks have not increased, misallocating the security budget.

DSpending on SCADA security controls should increase by 15%; application control spending

Increasing SCADA spending by 15% contradicts the trend showing SCADA attack growth has actually slowed to 7%, which does not justify a budget increase of that magnitude.

Concept tested: Security budget allocation based on threat trend analysis

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#SCADA security#threat trends#risk analysis#security spending

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice