PT0-003 · Question #246
A penetration tester must identify vulnerabilities within an ICS that is not connected to the internet or enterprise network. Which of the following should the tester utilize to conduct the testing?
The correct answer is D. Manual assessment. In an Isolated Industrial Control System (ICS) environment that is not connected to external networks, the safest and most effective approach is a manual assessment. This involves carefully reviewing configurations, firmware versions, and system behavior without using automated…
Question
A penetration tester must identify vulnerabilities within an ICS that is not connected to the internet or enterprise network. Which of the following should the tester utilize to conduct the testing?
Options
- AChannel scanning
- BStealth scans
- CSource code analysis
- DManual assessment
How the community answered
(23 responses)- A4% (1)
- B4% (1)
- C13% (3)
- D78% (18)
Explanation
In an Isolated Industrial Control System (ICS) environment that is not connected to external networks, the safest and most effective approach is a manual assessment. This involves carefully reviewing configurations, firmware versions, and system behavior without using automated or intrusive tools that might disrupt fragile ICS components.
Topics
Community Discussion
No community discussion yet for this question.