Security Cybersecurity Threats and Vulnerabilities Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Cybersecurity Threats and Vulnerabilities flashcards as text
What type of malware was specifically designed to target Siemens PLCs and disrupt Iranian nuclear centrifuges?
Answer: Stuxnet
Stuxnet was a sophisticated worm discovered in 2010 that targeted Siemens S7 PLCs controlling uranium enrichment centrifuges.
Which attack technique involves an adversary manipulating sensor data sent to a control system to cause incorrect automated responses?
Answer: False data injection
False data injection attacks corrupt the integrity of sensor readings, causing control systems to make decisions based on manipulated inputs.
What is 'island hopping' in the context of ICS attacks?
Answer: Using a less-secure partner or vendor network to pivot into the target ICS
Island hopping uses a target's trusted third-party suppliers or partners as an entry point to reach the primary ICS environment.
The TRITON/TRISIS malware was notable because it specifically targeted which ICS component?
Answer: Safety Instrumented Systems (SIS)
TRITON targeted Schneider Electric Triconex Safety Instrumented Systems, aiming to disable safety shutdowns and enable physical damage.
Which vulnerability category is most prevalent in legacy ICS environments due to the age of the installed equipment?
Answer: Unpatched software and firmware
Legacy ICS devices often run outdated firmware and OS versions that cannot be patched without disrupting operations, leaving known vulnerabilities unaddressed.
What is a 'watering hole' attack as it applies to ICS threat vectors?
Answer: Compromising websites frequently visited by ICS engineers to deliver malware
A watering hole attack compromises websites that ICS personnel commonly visit, using drive-by downloads to infect their workstations and gain ICS network access.
Which characteristic of ICS protocols like Modbus and DNP3 makes them especially vulnerable to spoofing attacks?
Answer: They lack built-in authentication mechanisms
Legacy protocols like Modbus and DNP3 were designed for reliability in trusted environments and have no authentication, allowing any device on the network to send commands.