CAS-003 · Question #881
Two major aircraft manufacturers are in the process of merging their assets and forming a single enterprise network. One of the manufacturers maintains its ICS systems on the same network segment as…
The correct answer is A. The ICS components are unsupported and vulnerable, and they cannot be patched. ICS (Industrial Control Systems) are notoriously built on legacy hardware and software that vendors no longer support or patch. This makes them inherently vulnerable regardless of network topology. The key architectural weakness when merging these two companies is not the…
Question
Two major aircraft manufacturers are in the process of merging their assets and forming a single enterprise network. One of the manufacturers maintains its ICS systems on the same network segment as its enterprise IT assets, whereas the other manufacturer has physically isolated its factory-floor ICS systems from the rest of its enterprise. Which of the following BEST describes an architectural weakness associated with merging the two companies' assets in their current state?
Options
- AThe ICS components are unsupported and vulnerable, and they cannot be patched.
- BThe employed network segmentation does not use cryptographic isolation.
- CThe IT systems across the two organizations run different security architectures.
- DSome factory-floor systems are incompatible with legacy protocols
How the community answered
(30 responses)- A43% (13)
- B20% (6)
- C7% (2)
- D30% (9)
Explanation
ICS (Industrial Control Systems) are notoriously built on legacy hardware and software that vendors no longer support or patch. This makes them inherently vulnerable regardless of network topology. The key architectural weakness when merging these two companies is not the difference in segmentation approaches (one uses an air gap, one does not), but that both companies' ICS systems almost certainly run on end-of-life platforms that cannot be patched. Option B is wrong because physical air-gapping is a valid and often preferred segmentation method that doesn't require cryptographic isolation. Option C is a general observation, not a specific weakness. Option D describes a protocol compatibility issue, not an architectural vulnerability. The inability to patch is the root architectural flaw that merging exposes.
Topics
Community Discussion
No community discussion yet for this question.