nerdexam
CompTIA

PT0-002 · Question #557

While performing a vulnerability assessment over an OT/ICS environment, the tester runs a tool that causes a malfunction on one of the systems in charge of water pumping at the plant. Which of the…

The correct answer is C. Changing the scanning approach to use passive-only scans and tools. OT (Operational Technology) and ICS (Industrial Control Systems) environments are sensitive and designed for reliability and availability. Active scanning tools and techniques commonly used in IT environments can inadvertently cause disruptions, such as system malfunctions or…

Information Gathering and Vulnerability Scanning

Question

While performing a vulnerability assessment over an OT/ICS environment, the tester runs a tool that causes a malfunction on one of the systems in charge of water pumping at the plant. Which of the following is the best way to avoid these disruptions in future engagements?

Options

  • AUsing Nmap or other scanning solutions that also are used on IT environments
  • BNot testing water pumps or other OT/ICS devices that are critical
  • CChanging the scanning approach to use passive-only scans and tools
  • DIncluding disruption of services on the SOW

How the community answered

(59 responses)
  • A
    7% (4)
  • B
    2% (1)
  • C
    81% (48)
  • D
    10% (6)

Explanation

OT (Operational Technology) and ICS (Industrial Control Systems) environments are sensitive and designed for reliability and availability. Active scanning tools and techniques commonly used in IT environments can inadvertently cause disruptions, such as system malfunctions or crashes, because OT/ICS devices may not handle intrusive traffic well. To minimize the risk of disruptions: - A passive-only scanning approach involves tools that monitor network traffic without actively interacting with devices. This avoids the risks associated with intrusive probing and ensures the stability of critical systems. - Tools like Tenable.ot or Nozomi Networks focus on passive monitoring for vulnerabilities and misconfigurations without interfering with normal operations.

Topics

#OT/ICS Security#Vulnerability Scanning#Passive Scanning#Risk Mitigation

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice