nerdexam
CompTIA

PT0-003 · Question #246

A penetration tester must identify vulnerabilities within an ICS that is not connected to the internet or enterprise network. Which of the following should the tester utilize to conduct the testing?

The correct answer is D. Manual assessment. In an Isolated Industrial Control System (ICS) environment that is not connected to external networks, the safest and most effective approach is a manual assessment. This involves carefully reviewing configurations, firmware versions, and system behavior without using automated…

Submitted by mateo_ar· Mar 6, 2026Vulnerability discovery and analysis

Question

A penetration tester must identify vulnerabilities within an ICS that is not connected to the internet or enterprise network. Which of the following should the tester utilize to conduct the testing?

Options

  • AChannel scanning
  • BStealth scans
  • CSource code analysis
  • DManual assessment

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    13% (3)
  • D
    78% (18)

Explanation

In an Isolated Industrial Control System (ICS) environment that is not connected to external networks, the safest and most effective approach is a manual assessment. This involves carefully reviewing configurations, firmware versions, and system behavior without using automated or intrusive tools that might disrupt fragile ICS components.

Topics

#ICS security#Offline assessment#Manual testing#Vulnerability assessment

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice