nerdexam
CompTIA

CAS-003 · Question #894

A legacy SCADA system is m place in a manufacturing facility to ensure proper facility operations. Recent industry reports made available to the security team state similar legacy systems are being…

The correct answer is D. Network-based intrusion detection systems. For legacy SCADA systems where endpoint agents cannot be installed, a network-based intrusion detection system provides continuous, passive threat monitoring without requiring modification to the legacy devices.

Enterprise Security Operations

Question

A legacy SCADA system is m place in a manufacturing facility to ensure proper facility operations. Recent industry reports made available to the security team state similar legacy systems are being used as part of an attack chain in the same industry market. Due to the age of these devices security control options are limited. Which of the following would BEST provide continuous monitoring for these threats?

Options

  • AFull packet captures and log analysis
  • BPassive vulnerability scanners
  • CRed-team threat hunting
  • DNetwork-based intrusion detection systems

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    14% (5)
  • D
    78% (28)

Why each option

For legacy SCADA systems where endpoint agents cannot be installed, a network-based intrusion detection system provides continuous, passive threat monitoring without requiring modification to the legacy devices.

AFull packet captures and log analysis

Full packet capture and log analysis are forensic and investigative tools that require significant storage and human analysis - they do not provide automated, real-time continuous threat detection.

BPassive vulnerability scanners

Passive vulnerability scanners identify configuration weaknesses and unpatched software but do not detect active intrusion attempts or ongoing attack activity in real time.

CRed-team threat hunting

Red-team threat hunting is a periodic, human-driven adversarial simulation exercise and does not provide continuous automated monitoring of live network threats.

DNetwork-based intrusion detection systemsCorrect

A network-based intrusion detection system (NIDS) passively monitors network traffic for known attack signatures and anomalous behavior without requiring any software installation on the legacy SCADA devices themselves - making it the best fit for environments where endpoint security controls are limited due to device age or vendor restrictions.

Concept tested: Continuous monitoring for legacy ICS/SCADA systems

Source: https://www.cisa.gov/sites/default/files/publications/Cyber_Threats_to_OT.pdf

Topics

#SCADA security#ICS monitoring#network IDS#continuous monitoring

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice