nerdexam
CompTIA

CAS-003 · Question #906

The Chief Information Security Officer (CISO) of a power generation facility s concerned about being able to detect missing security updates on the critical infrastructure in use at the facility…

The correct answer is C. Deploying a data diode for internal websites. A data diode enforces strictly one-way data flow at the hardware level - data can only travel in one direction across the boundary. Deploying a data diode for internal (patch/vulnerability) websites allows the ICS/SCADA systems to receive update status and security information…

Technical Integration of Enterprise Security

Question

The Chief Information Security Officer (CISO) of a power generation facility s concerned about being able to detect missing security updates on the critical infrastructure in use at the facility. Most of this critical infrastructure consists of ICS and SCADA systems that are maintained by vendors, and the vendors have warned the CISO that proxying network traffic is likely to cause a DoS condition. Which of the following would be BEST to address the CISO s concerns while keeping the critical systems functional?

Options

  • AConfiguring the existing SIEM to ingest al log files property
  • BImplementing a passive vulnerability scanning solution
  • CDeploying a data diode for internal websites
  • DAdding more frequent antivirus and anti-malware signature updates
  • EAdjusting Me access rules to use the concept of least privilege

How the community answered

(30 responses)
  • A
    13% (4)
  • B
    7% (2)
  • C
    53% (16)
  • D
    3% (1)
  • E
    23% (7)

Explanation

A data diode enforces strictly one-way data flow at the hardware level - data can only travel in one direction across the boundary. Deploying a data diode for internal (patch/vulnerability) websites allows the ICS/SCADA systems to receive update status and security information from the internal network without any return traffic flowing back toward the sensitive systems. This architecture satisfies the CISO's need to assess patch levels while completely eliminating the risk of bidirectional traffic that vendors warned could cause a DoS. Option B (passive vulnerability scanning) is tempting but even passive scanners inject some traffic; vendors explicitly flagged network traffic as the risk. Option A (SIEM log ingestion) improves visibility but does not directly address patch-level detection. Option D (AV signatures) and Option E (least privilege) do not address the patch detection requirement.

Topics

#SCADA#passive vulnerability scanning#data diode#critical infrastructure

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice