nerdexam
CompTIA

CAS-003 · Question #627

A manufacturing company's security engineer is concerned a remote actor may be able to access the ICS that is used to monitor the factory lines. The security engineer recently proposed some…

The correct answer is D. Running frequent vulnerability scans during the project. Demonstrating progressive attack surface reduction across multiple ICS implementation phases requires continuous, quantifiable measurement rather than point-in-time assessments.

Risk Management

Question

A manufacturing company's security engineer is concerned a remote actor may be able to access the ICS that is used to monitor the factory lines. The security engineer recently proposed some techniques to reduce the attack surface of the ICS to the Chief Information Security Officer (CISO). Which of the following would BEST track the reductions to show the CISO the engineer's plan is successful during each phase?

Options

  • AConducting tabletop exercises to evaluate system risk
  • BContracting a third-party auditor after the project is finished
  • CPerforming pre- and post-implementation penetration tests
  • DRunning frequent vulnerability scans during the project

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    20% (4)
  • D
    70% (14)

Why each option

Demonstrating progressive attack surface reduction across multiple ICS implementation phases requires continuous, quantifiable measurement rather than point-in-time assessments.

AConducting tabletop exercises to evaluate system risk

Tabletop exercises evaluate hypothetical incident response scenarios and risk reasoning but do not produce quantifiable attack surface metrics to track phase-by-phase reductions.

BContracting a third-party auditor after the project is finished

A third-party audit scheduled only after project completion cannot provide visibility into incremental progress during each intermediate implementation phase.

CPerforming pre- and post-implementation penetration tests

Pre- and post-implementation penetration tests capture only two data points in time and cannot show the incremental, per-phase improvements the CISO requires.

DRunning frequent vulnerability scans during the projectCorrect

Running frequent vulnerability scans throughout the project generates ongoing, measurable data showing the number and severity of identified vulnerabilities decreasing at each implementation phase. This continuous baseline allows the security engineer to present the CISO with clear, phase-by-phase evidence that each defensive change is having the intended effect. Vulnerability scanning directly quantifies attack surface components such as open ports, unpatched services, and weak configurations on the ICS.

Concept tested: ICS attack surface reduction measurement and tracking

Source: https://csrc.nist.gov/pubs/sp/800/82/r3/final

Topics

#ICS security#vulnerability scanning#attack surface reduction#metrics

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice