nerdexam
CompTIA

CAS-003 · Question #35

An architect was recently hired by a power utility to increase the security posture of the company's power generation and distribution sites. Upon review, the architect identifies legacy hardware…

The correct answer is B. Install a firewall and IDS between systems and the LAN E. Configure the systems to use government-hosted NTP servers. This question involves securing legacy OT/ICS systems that cannot be upgraded and must remain operational. Option A (isolate on own network) is tempting but would conflict with the requirement to pull from Internet time sources. Option C (own stratum-0/stratum-1 NTP servers) is…

Enterprise Security Architecture

Question

An architect was recently hired by a power utility to increase the security posture of the company's power generation and distribution sites. Upon review, the architect identifies legacy hardware with highly vulnerable and unsupported software driving critical operations. These systems must exchange data with each other, be highly synchronized, and pull from the Internet time sources. Which of the following architectural decisions would BEST reduce the likelihood of a successful attack without harming operational capability? (Choose two.)

Options

  • AIsolate the systems on their own network
  • BInstall a firewall and IDS between systems and the LAN
  • CEmploy own stratum-0 and stratum-1 NTP servers
  • DUpgrade the software on critical systems
  • EConfigure the systems to use government-hosted NTP servers

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    47% (17)
  • C
    17% (6)
  • D
    31% (11)

Explanation

This question involves securing legacy OT/ICS systems that cannot be upgraded and must remain operational. Option A (isolate on own network) is tempting but would conflict with the requirement to pull from Internet time sources. Option C (own stratum-0/stratum-1 NTP servers) is incorrect because stratum-0 devices use GPS or atomic clocks - not internet sources - which would violate the stated requirement to pull from the Internet. Option D (upgrade software) is explicitly ruled out by 'unsupported software driving critical operations,' as upgrades risk breaking operational capability. Option B (firewall and IDS between systems and LAN) is correct because it adds a security layer that filters and monitors traffic without disrupting data exchange between systems. Option E (government-hosted NTP servers such as time.nist.gov) is correct because it satisfies the mandatory internet time requirement while routing synchronization through the most trusted and hardened sources available, reducing the risk of NTP-based attacks like spoofing or man-in-the-middle.

Topics

#ICS/SCADA security#network segmentation#NTP security#OT security

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice