Which of the following BEST describes some significant security weaknesses with an ICS, such as those used in electrical utility facilities, natural gas facilities, dams, and nuclear facilities?
A.
ICS vendors are slow to implement adequate security controls.
B.
ICS staff are not adequately trained to perform basic duties.
C.
There is a scarcity of replacement equipment for critical devices.
D.
There is a lack of compliance for ICS facilities.
Don't see how adequate security controls are the purview of vendors. A quick c/p of "ICS security problems" into google shows many papers and sites describing how credential mgmt is subpar, networks arent segregrated, etc...I say eliminate A as vendors are not responsible for controls...then elim D as these places are burdened with massive compliance regulations and elim C since there is absolutely no reason to believe equipment is scarce ....you are left with but 1 answer
I would go for A. - "On average, vendors take a rather long time to fix vulnerabilities (more than six months) Elimination of some vulnerabilities—measured by time from vendor notification to release of a patch—can take more than two years. For end users, such protracted responses increase the risk of exploitation of device vulnerabilities."
https://www.ptsecurity.com/ww-en/analytics/ics-vulnerabilities-2019/
I would say "A" after reading the following.
The highest percentage of vulnerabilities identified in ICS product
assessments continues to be improper input validation by ICS code. Poor access
controls—credentials management and security configuration—were the second
most common security weakness identified in new ICS software in 2009–2010.
Authentication weaknesses follow in third place. However, vulnerabilities
reported from the previous CSSP ICS product assessments include more patch
management problems than the more recent findings.
https://us-cert.cisa.gov/sites/default/files/recommended_practices/DHS_Common_Cybersecurity_Vulnerabilities_ICS_2010.pdf
"The highest percentage of vulnerabilities identified in ICS product
assessments continues to be improper input validation by ICS code. Poor access
controls—credentials management and security configuration—were the second
most common security weakness identified in new ICS software in 2009–2010.
Authentication weaknesses follow in third place. However, vulnerabilities
reported from the previous CSSP ICS product assessment."
https://us-cert.cisa.gov/sites/default/files/recommended_practices/DHS_Common_Cybersecurity_Vulnerabilities_ICS_2010.pdf
"Many ICSs were established years before security standards were established, and as a result, are considerably outdated."
Correct answer seems to be A.
I would agree that is is B. The BEST answer is almost always training and the human factor when it comes to security. The slow implementation could be caused by inadequate training.
It doesn't really mention that. It says "perform basic duties"; not specifically referring to security but their job in general. It's heavily implying they are truly incompetent employees in every aspect. In my experience people working in those type of fields are very siloed and really know their job role well.
This section is not available anymore. Please use the main Exam Page.PT0-001 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
phatboy
Highly Voted 5Â years, 4Â months agowho__cares123456789___
4Â years, 3Â months agomr_robot
Highly Voted 5Â years agokloug
Most Recent 2Â years, 2Â months agomiabe
2Â years, 9Â months agonataldogomes
3Â years, 1Â month agoCybersec1989
3Â years, 7Â months ago9SH4
3Â years, 6Â months agophish7827
3Â years, 8Â months agoamericaman80
3Â years, 11Â months agonakres64
4Â years agobigwilly69
4Â years, 4Â months agoboboloboli
4Â years, 7Â months agoAcidscars
4Â years, 4Â months agoTheThreatGuy
4Â years, 3Â months agojon34thna
5Â years, 2Â months agoD1960
5Â years, 2Â months ago