nerdexam
CompTIA

CAS-003 · Question #905

The HVAC and fire suppression systems that were recently deployed at multiple locations are susceptible to a new vulnerability. A security engineer needs to ensure the vulnerability is not…

The correct answer is D. Create an IPS profile for the HVAC devices that includes the signatures. Because exploit signatures for this specific vulnerability are already available, deploying an IPS profile targeting those signatures is the fastest and most targeted first response - it provides immediate detection and blocking of active exploitation attempts without requiring…

Technical Integration of Enterprise Security

Question

The HVAC and fire suppression systems that were recently deployed at multiple locations are susceptible to a new vulnerability. A security engineer needs to ensure the vulnerability is not exploited. The devices are directly managed by a smart controller and do not need access to other pans of the network. Signatures are available to detect this vulnerability. Which of the following should be the FIRST step mi completing the request?

Options

  • ADeploy a NAC solution that disables devices with unknown MACs
  • BCreate a firewall policy with access to the smart controller from the internal network only.
  • CCreate a segmented subnet for all HVAC devices and the smart controller
  • DCreate an IPS profile for the HVAC devices that includes the signatures

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    14% (3)
  • D
    76% (16)

Explanation

Because exploit signatures for this specific vulnerability are already available, deploying an IPS profile targeting those signatures is the fastest and most targeted first response - it provides immediate detection and blocking of active exploitation attempts without requiring infrastructure changes. Option C (creating a segmented subnet) is a sound long-term architectural control, but subnetting is a more disruptive change that takes time to plan and implement correctly. Option B (firewall policy) also requires careful design to avoid disrupting smart controller communication. Option A (NAC by MAC address) is easily bypassed by MAC spoofing and does not address the vulnerability directly. The principle here is to use the fastest available mitigating control first (IPS with known signatures), then layer in architectural controls like segmentation as a follow-on hardening step.

Topics

#ICS/SCADA#OT security#IPS signatures#network segmentation

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice