nerdexam
CompTIA

CAS-003 · Question #671

An organization is integrating an ICS and wants to ensure the system is cyber resilient. Unfortunately, many of the specialized components are legacy systems that cannot be patched. The existing…

The correct answer is A. Vulnerable components. When integrating legacy ICS components that cannot be patched, the foundational design assumption that MUST be made is that those components are and will remain vulnerable. Accepting this as a given constraint allows the security architect to design compensating controls around…

Enterprise Security Architecture

Question

An organization is integrating an ICS and wants to ensure the system is cyber resilient. Unfortunately, many of the specialized components are legacy systems that cannot be patched. The existing enterprise consists of mission-critical systems that require 99.9% uptime. To assist in the appropriate design of the system given the constraints, which of the following MUST be assumed?

Options

  • AVulnerable components
  • BOperational impact due to attack
  • CTime criticality of systems
  • DPresence of open-source software

How the community answered

(50 responses)
  • A
    82% (41)
  • B
    4% (2)
  • C
    4% (2)
  • D
    10% (5)

Explanation

When integrating legacy ICS components that cannot be patched, the foundational design assumption that MUST be made is that those components are and will remain vulnerable. Accepting this as a given constraint allows the security architect to design compensating controls around those components - such as network segmentation, unidirectional gateways, application whitelisting, and anomaly detection - rather than relying on patching. Operational impact due to attack (B) and time criticality (C) are important considerations but are consequences of the vulnerability, not the root assumption driving the design. The presence of open-source software (D) is not inherently relevant to legacy ICS resilience design.

Topics

#ICS security#legacy systems#cyber resilience#OT vulnerability management

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice