ICS Surveillance & Monitoring Systems 3 — Questions and Answers
Question 1: Which network architecture practice BEST protects ICS monitoring systems from cyber threats originating on the corporate IT network?
- Implementing a demilitarized zone (DMZ) between IT and OT networks (Correct answer)
- Allowing bidirectional traffic between IT and OT on port 80 only
- Sharing a single flat network with VLAN tagging
- Using the same Active Directory domain for IT and OT systems
Correct answer: Implementing a demilitarized zone (DMZ) between IT and OT networks
A DMZ acts as a buffer zone, controlling data flows between the untrusted corporate network and the critical OT monitoring environment.
Question 2: In ICS monitoring, what is a 'data diode' used for?
- Allowing data to flow in only one direction, from OT to IT, without any return path (Correct answer)
- Filtering out malicious packets bidirectionally
- Encrypting historian data before transmission
- Providing redundant network paths for high availability
Correct answer: Allowing data to flow in only one direction, from OT to IT, without any return path
A data diode is a hardware-enforced unidirectional gateway that ensures data can only travel from the ICS network outward, eliminating the return attack path.
Question 3: An operator notices that a flow meter reading in the SCADA HMI has been constant for 6 hours without variation. What security concern should this raise?
- A sensor or its data feed may have been spoofed or frozen by an attacker (Correct answer)
- The process has reached a stable steady state
- The historian is compressing redundant data
- The HMI display needs to be refreshed
Correct answer: A sensor or its data feed may have been spoofed or frozen by an attacker
A perfectly flat reading over an extended period is a hallmark indicator of sensor spoofing or data substitution attacks targeting ICS monitoring.
Question 4: What is the purpose of 'out-of-band' monitoring in ICS security surveillance?
- Using a separate, dedicated network to monitor ICS devices without traversing the operational network (Correct answer)
- Monitoring ICS systems only during scheduled maintenance windows
- Sending alerts via SMS rather than email
- Analyzing data after it has been archived to long-term storage
Correct answer: Using a separate, dedicated network to monitor ICS devices without traversing the operational network
Out-of-band monitoring uses a dedicated management network so that surveillance traffic does not interfere with or traverse the production ICS network.
Question 5: Which type of ICS monitoring system is specifically designed to detect anomalies by establishing a behavioral baseline of normal OT network communications?
- OT-specific Intrusion Detection System (IDS) with passive monitoring (Correct answer)
- Traditional IT antivirus software
- Network-attached storage (NAS) audit logs
- SNMP polling at 5-minute intervals
Correct answer: OT-specific Intrusion Detection System (IDS) with passive monitoring
OT-specific passive IDS tools learn normal communication patterns between ICS devices and alert on deviations without disrupting real-time control traffic.
Question 6: A security engineer is reviewing camera placements at a water treatment facility. Which location should receive the HIGHEST monitoring priority from a security standpoint?
- Chemical dosing control panels and pump control rooms (Correct answer)
- Employee break rooms and parking lots
- Administrative office hallways
- Shipping and receiving docks for non-chemical deliveries
Correct answer: Chemical dosing control panels and pump control rooms
Chemical dosing and pump control areas represent the highest-consequence physical access points because tampering could directly impact public safety.
Question 7: What logging feature is most critical for forensic investigation of a suspected ICS cyberattack that manipulated sensor readings?
- Tamper-evident, time-synchronized logs stored on a write-once medium or remote SIEM (Correct answer)
- Logs stored locally on the affected HMI workstation
- Periodic manual log exports to a USB drive
- Compressed log archives with weekly rotation
Correct answer: Tamper-evident, time-synchronized logs stored on a write-once medium or remote SIEM
Tamper-evident logs with precise time synchronization stored off the compromised system are essential for reliable forensic reconstruction of attack timelines.
Which network architecture practice BEST protects ICS monitoring systems from cyber threats originating on the corporate IT network?