ICS Cheat Sheet 2026

The 30 highest-yield ICS facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

75 questions
120 min time limit
70.00% to pass
  1. ISA/IEC 62443-3-3 Security Level 2 requires protection against which threat actor category? → Intentional violation using simple means by an entity with low motivation
  2. Which report type would BEST communicate recurring patch management gaps across multiple ICS sites to senior leadership? → A trend analysis report showing patch compliance rates over time with risk context
  3. What distinguishes a 'passive infrared' (PIR) sensor from an 'active infrared' sensor in ICS perimeter protection? → PIR sensors detect emitted body heat; active sensors transmit and receive IR beams
  4. What is the primary purpose of a demilitarized zone (DMZ) in an ICS network architecture? → To host historian servers accessible from both OT and IT networks
  5. During forensic evidence collection after an ICS incident, why is it important to document the chain of custody? → To preserve evidence integrity for potential legal proceedings or regulatory reporting
  6. Which threat actor group is historically associated with the CRASHOVERRIDE/Industroyer malware targeting electric grid ICS? → Sandworm (Russia)
  7. How should security incidents be handled? → Following an established incident response plan with documentation
  8. Which federal regulation requires cybersecurity programs for pipeline facilities, including ICS/SCADA systems? → TSA Pipeline Security Directives
  9. Why is documentation critical in compliance efforts? → Supports audits and accountability
  10. Under the NIST SP 800-53 control family, which control family is MOST directly applicable to ICS physical access to control rooms? → Physical and Environmental Protection (PE)
  11. Which factor is most important when determining treatment frequency? → Evidence-based clinical guidelines and patient response
  12. What is the PRIMARY security purpose of installing anti-ram bollards at the entrance of a critical ICS facility? → Stopping vehicle-borne improvised explosive device (VBIED) or ram-raid attacks
  13. An ICS facility uses wireless sensors for remote area monitoring. Which security control is MOST critical to implement for these devices? → Mutual authentication and encrypted communications between sensors and the gateway
  14. After containing an ICS cyber incident, what is the NEXT phase in the incident response lifecycle? → Eradication
  15. What is the impact of denial-of-service (DoS) attacks on ICS? → Loss of system availability
  16. When designing firewall rules for an ICS ESP, which rule-base philosophy is mandated by NERC CIP and recommended by ICS security frameworks? → Default-deny with explicit allow rules for required communications only
  17. What is the function of a 'dead man' alarm in a remote ICS field site? → Triggers when a field technician fails to check in within a defined interval
  18. How should a Industrial Control Systems Security professional handle situations beyond their expertise? → Refer to a qualified specialist and communicate transparently with the client
  19. Which framework provides a common language for managing cybersecurity risk? → NIST Cybersecurity Framework
  20. How should treatment protocols be modified for patients with comorbidities? → Adjust parameters based on individual risk factors and contraindications
  21. What is the primary purpose of maintaining accurate professional documentation? → To create a legal record of services and support continuity of care
  22. What is the recommended retention period guidance for ICS security incident records under NERC CIP standards? → 3 years
  23. What is the significance of professional networking in the Industrial Control Systems Security field? → It facilitates knowledge exchange, referrals, and collaborative problem-solving
  24. Which attack technique specifically targets ICS monitoring systems to make operators believe a process is running normally while malicious activity occurs? → False data injection (FDI) attack
  25. In ICS environments, what is the recommended approach when a vendor-issued patch cannot be applied immediately to a critical control system? → Apply compensating controls such as enhanced monitoring and network restrictions
  26. Which standard focuses specifically on control system cybersecurity? → ISA/IEC 62443
  27. An ICS organization must notify the Department of Homeland Security (DHS) CISA about a significant cyber incident within 72 hours under which regulation? → CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
  28. What is the primary security risk of connecting an IP surveillance camera directly to an ICS control network without segmentation? → Cameras can serve as pivot points for attackers to reach control systems
  29. In OT security, which property is typically prioritized above the traditional IT security triad? → Availability
  30. During an ICS vulnerability assessment, a scanner detects an open port 102 on a device. What protocol and associated risk should the analyst investigate? → S7comm — susceptibility to Siemens PLC manipulation
Turn these facts into recall:
Was this helpful?