CAS-003 · Question #906
The Chief Information Security Officer (CISO) of a power generation facility s concerned about being able to detect missing security updates on the critical infrastructure in use at the facility…
The correct answer is C. Deploying a data diode for internal websites. A data diode enforces strictly one-way data flow at the hardware level - data can only travel in one direction across the boundary. Deploying a data diode for internal (patch/vulnerability) websites allows the ICS/SCADA systems to receive update status and security information…
Question
The Chief Information Security Officer (CISO) of a power generation facility s concerned about being able to detect missing security updates on the critical infrastructure in use at the facility. Most of this critical infrastructure consists of ICS and SCADA systems that are maintained by vendors, and the vendors have warned the CISO that proxying network traffic is likely to cause a DoS condition. Which of the following would be BEST to address the CISO s concerns while keeping the critical systems functional?
Options
- AConfiguring the existing SIEM to ingest al log files property
- BImplementing a passive vulnerability scanning solution
- CDeploying a data diode for internal websites
- DAdding more frequent antivirus and anti-malware signature updates
- EAdjusting Me access rules to use the concept of least privilege
How the community answered
(30 responses)- A13% (4)
- B7% (2)
- C53% (16)
- D3% (1)
- E23% (7)
Explanation
A data diode enforces strictly one-way data flow at the hardware level - data can only travel in one direction across the boundary. Deploying a data diode for internal (patch/vulnerability) websites allows the ICS/SCADA systems to receive update status and security information from the internal network without any return traffic flowing back toward the sensitive systems. This architecture satisfies the CISO's need to assess patch levels while completely eliminating the risk of bidirectional traffic that vendors warned could cause a DoS. Option B (passive vulnerability scanning) is tempting but even passive scanners inject some traffic; vendors explicitly flagged network traffic as the risk. Option A (SIEM log ingestion) improves visibility but does not directly address patch-level detection. Option D (AV signatures) and Option E (least privilege) do not address the patch detection requirement.
Topics
Community Discussion
No community discussion yet for this question.