CAS-003 · Question #894
A legacy SCADA system is m place in a manufacturing facility to ensure proper facility operations. Recent industry reports made available to the security team state similar legacy systems are being…
The correct answer is D. Network-based intrusion detection systems. For legacy SCADA systems where endpoint agents cannot be installed, a network-based intrusion detection system provides continuous, passive threat monitoring without requiring modification to the legacy devices.
Question
A legacy SCADA system is m place in a manufacturing facility to ensure proper facility operations. Recent industry reports made available to the security team state similar legacy systems are being used as part of an attack chain in the same industry market. Due to the age of these devices security control options are limited. Which of the following would BEST provide continuous monitoring for these threats?
Options
- AFull packet captures and log analysis
- BPassive vulnerability scanners
- CRed-team threat hunting
- DNetwork-based intrusion detection systems
How the community answered
(36 responses)- A6% (2)
- B3% (1)
- C14% (5)
- D78% (28)
Why each option
For legacy SCADA systems where endpoint agents cannot be installed, a network-based intrusion detection system provides continuous, passive threat monitoring without requiring modification to the legacy devices.
Full packet capture and log analysis are forensic and investigative tools that require significant storage and human analysis - they do not provide automated, real-time continuous threat detection.
Passive vulnerability scanners identify configuration weaknesses and unpatched software but do not detect active intrusion attempts or ongoing attack activity in real time.
Red-team threat hunting is a periodic, human-driven adversarial simulation exercise and does not provide continuous automated monitoring of live network threats.
A network-based intrusion detection system (NIDS) passively monitors network traffic for known attack signatures and anomalous behavior without requiring any software installation on the legacy SCADA devices themselves - making it the best fit for environments where endpoint security controls are limited due to device age or vendor restrictions.
Concept tested: Continuous monitoring for legacy ICS/SCADA systems
Source: https://www.cisa.gov/sites/default/files/publications/Cyber_Threats_to_OT.pdf
Topics
Community Discussion
No community discussion yet for this question.