CAS-003 · Question #824
An ICS security engineer is performing assessment at a bank in Chicago. The engineer reviews the following output: Which of the following tools is the engineer using to provide this output?
The correct answer is B. Shodan. Shodan (B) is a specialized internet search engine that continuously scans and indexes internet-connected devices, collecting banner information, open ports, service versions, and device metadata - including ICS/SCADA systems, industrial controllers, and critical infrastructure…
Question
An ICS security engineer is performing assessment at a bank in Chicago. The engineer reviews the following output:
Which of the following tools is the engineer using to provide this output?
Exhibit
Options
- ASCAP scanner
- BShodan
- CFuzzer
- DVulnerability scanner
How the community answered
(52 responses)- A8% (4)
- B88% (46)
- C2% (1)
- D2% (1)
Explanation
Shodan (B) is a specialized internet search engine that continuously scans and indexes internet-connected devices, collecting banner information, open ports, service versions, and device metadata - including ICS/SCADA systems, industrial controllers, and critical infrastructure equipment. For an ICS security assessment at a bank, an engineer would use Shodan to identify which industrial control systems or operational technology devices are inadvertently exposed to the public internet. The output format of Shodan (showing IP addresses, ports, banners, geographic location, and device type) matches what is described. A SCAP scanner (A) assesses configuration compliance against benchmarks. A fuzzer (C) generates malformed inputs to test for software vulnerabilities. A vulnerability scanner (D) actively probes systems for known CVEs. Shodan is passive and discovery-focused, fitting the described output.
Topics
Community Discussion
No community discussion yet for this question.
