nerdexam
CompTIA

CAS-003 · Question #716

A manufacturing company employs SCADA systems to drive assembly lines across geographically dispersed sites. Therefore, the company must use the Internet to transport control messages and responses…

The correct answer is A. Design a patch management capability for control systems. E. Isolate control systems from enterprise systems. Patch management reduces exploitable vulnerabilities in SCADA software, and network isolation creates a security boundary that limits lateral movement from enterprise systems into the OT environment.

Enterprise Security Architecture

Question

A manufacturing company employs SCADA systems to drive assembly lines across geographically dispersed sites. Therefore, the company must use the Internet to transport control messages and responses. Which of the following architectural changes when integrated will BEST reduce the manufacturing control system's attack surface? (Select TWO)

Options

  • ADesign a patch management capability for control systems.
  • BImplement supply chain security.
  • CIntegrate message authentication
  • DAdd sensors and collectors at the Internet boundary.
  • EIsolate control systems from enterprise systems.
  • FImplement a site-to-site VPN across sites

How the community answered

(24 responses)
  • A
    67% (16)
  • B
    8% (2)
  • D
    4% (1)
  • F
    21% (5)

Why each option

Patch management reduces exploitable vulnerabilities in SCADA software, and network isolation creates a security boundary that limits lateral movement from enterprise systems into the OT environment.

ADesign a patch management capability for control systems.Correct

A formalized patch management capability ensures SCADA firmware and software receive timely security updates, reducing the number of known CVEs that an Internet-based attacker can exploit against exposed control system endpoints.

BImplement supply chain security.

Supply chain security addresses the integrity of hardware and software during procurement and distribution, but it does not reduce the runtime network attack surface of already-deployed SCADA systems that are currently exposed to Internet traffic.

CIntegrate message authentication

Message authentication verifies the integrity and origin of individual control messages in transit, but it is a compensating control rather than an architectural change that reduces the overall number of systems or network vectors exposed to attack.

DAdd sensors and collectors at the Internet boundary.

Adding sensors and collectors at the Internet boundary increases visibility and detection capability but does not remove or restrict any attack vector - the attack surface itself remains unchanged by this monitoring addition.

EIsolate control systems from enterprise systems.Correct

Isolating control systems from enterprise IT networks establishes a dedicated OT security zone with strict ingress and egress controls, preventing an enterprise compromise from propagating laterally into the manufacturing control environment and significantly shrinking the reachable attack surface.

FImplement a site-to-site VPN across sites

A site-to-site VPN encrypts the Internet transport channel but all SCADA endpoints remain reachable through the established tunnel, so a compromise of any VPN-connected site still provides access paths into the control systems.

Concept tested: ICS/SCADA attack surface reduction through isolation and patch management

Source: https://www.cisa.gov/topics/industrial-control-systems

Topics

#SCADA security#ICS/OT isolation#site-to-site VPN#patch management

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice