โ† All ICS Flashcard Decks

Security Network Architecture and Protocols Flashcards

7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Network Architecture and Protocols flashcards as text
  1. Which ICS protocol transmits data in plaintext and is therefore considered inherently insecure?

    Answer: Modbus TCP

    Modbus TCP lacks built-in authentication or encryption, transmitting all data in plaintext.

  2. What is the primary purpose of a demilitarized zone (DMZ) in an ICS network architecture?

    Answer: To host historian servers accessible from both OT and IT networks

    An ICS DMZ hosts shared services like historians so neither the IT nor OT network directly communicates with the other.

  3. In the Purdue Reference Model, which level hosts supervisory control functions such as SCADA servers and HMIs?

    Answer: Level 2

    Level 2 of the Purdue Model is the Supervisory Control level, housing SCADA systems and HMIs.

  4. A defense-in-depth strategy for ICS networks primarily relies on which concept?

    Answer: Layered security controls across multiple zones

    Defense-in-depth applies multiple overlapping security controls so that failure of one layer does not compromise the entire system.

  5. Which protocol is commonly used for secure remote access tunneling into ICS environments?

    Answer: IPsec VPN

    IPsec VPN provides encrypted, authenticated tunnels for secure remote access into ICS environments.

  6. What network segmentation technique uses VLAN tagging to separate OT traffic from IT traffic on shared switches?

    Answer: IEEE 802.1Q

    IEEE 802.1Q VLAN tagging allows logical separation of OT and IT traffic on shared physical network infrastructure.

  7. Which attack targets ICS networks by exploiting the lack of authentication in legacy SCADA protocols to issue unauthorized commands?

    Answer: Spoofed command injection

    Spoofed command injection exploits unauthenticated legacy protocols to send fake control commands to PLCs or RTUs.