nerdexam
CompTIA

CAS-003 · Question #493

A manufacturing company recently recovered from an attack on its ICS devices. It has since reduced the attack surface by isolating the affected components. The company now wants to implement…

The correct answer is A. Trains on normal behavior and identifies deviations therefrom. Industrial Control Systems (ICS) environments have highly deterministic, repetitive communication patterns. Traditional signature-based commercial IDS products (option B) rely on known attack signatures and are poorly suited to ICS environments because ICS protocols are often…

Technical Integration of Enterprise Security

Question

A manufacturing company recently recovered from an attack on its ICS devices. It has since reduced the attack surface by isolating the affected components. The company now wants to implement detection capabilities. It is considering a system that is based on machine learning. Which of the following features would BEST describe the driver to adopt such nascent technology over mainstream commercial IDSs?

Options

  • ATrains on normal behavior and identifies deviations therefrom
  • BIdentifies and triggers upon known bad signatures and behaviors
  • CClassifies traffic based on logical protocols and messaging formats
  • DAutomatically reconfigures ICS devices based on observed behavior

How the community answered

(30 responses)
  • A
    60% (18)
  • B
    20% (6)
  • C
    13% (4)
  • D
    7% (2)

Explanation

Industrial Control Systems (ICS) environments have highly deterministic, repetitive communication patterns. Traditional signature-based commercial IDS products (option B) rely on known attack signatures and are poorly suited to ICS environments because ICS protocols are often proprietary, attacks may be novel, and generating signatures requires prior knowledge of the attack. A machine learning-based anomaly detection system learns what 'normal' looks like for that specific ICS environment (e.g., expected Modbus command sequences, communication intervals, device states) and flags deviations, making it effective against zero-day attacks and novel ICS-specific threats without requiring pre-existing signatures. Option C describes protocol analysis, which is a feature of some IDS but is not the unique driver for ML adoption. Option D describes automated response/reconfiguration, which is not a feature of an IDS and would be dangerous in an ICS environment.

Topics

#ICS security#machine learning IDS#anomaly detection#behavior baseline

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice