Access Control & Perimeter Security Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Access Control & Perimeter Security flashcards as text
Which ICS-specific challenge makes traditional role-based access control (RBAC) difficult to implement?
Answer: Many legacy controllers lack authentication capabilities entirely
Many legacy PLCs and RTUs were designed without authentication mechanisms, making enforcement of RBAC impossible without compensating controls like network segmentation.
A unidirectional security gateway (data diode) is best suited for which perimeter security scenario?
Answer: Transferring historian data from OT to IT without any return path
Data diodes enforce one-way data flow at the hardware level, making them ideal for replicating OT historian data to the IT network while physically preventing any inbound traffic.
In ICS environments, what is the PRIMARY risk of using shared accounts for HMI operator access?
Answer: Inability to attribute actions to specific individuals during incident investigation
Shared accounts eliminate individual accountability, making it impossible to determine which operator performed a specific action during a post-incident forensic review.
Which NERC CIP standard specifically addresses Electronic Security Perimeters (ESPs) for bulk electric system facilities?
Answer: CIP-005
NERC CIP-005 requires identification and protection of Electronic Security Perimeters, including controlling all Electronic Access Points into those perimeters.
What distinguishes a DMZ in an ICS architecture from a traditional IT DMZ?
Answer: ICS DMZs host services like historians and jump servers between OT and IT zones
An ICS DMZ hosts shared services (historians, remote access jump servers, file transfer zones) that bridge OT and IT networks while preventing direct connectivity between the two zones.
When implementing multi-factor authentication (MFA) for ICS remote access, which factor type raises the most operational concern in control room environments?
Answer: Something you are (biometric)
Biometric authentication in industrial environments can fail due to dirty hands, gloves, or extreme temperatures, creating operational barriers during time-critical emergency responses.
According to ISA/IEC 62443, what is a 'Security Level Target' (SL-T) used for?
Answer: Defining the required cybersecurity capability for a zone or conduit
SL-T defines the desired security capability level (SL 1-4) for a zone or conduit based on the threat model and consequences of compromise, driving the selection of appropriate countermeasures.