exam questions

Exam PT0-001 All Questions

View all questions & answers for the PT0-001 exam

Exam PT0-001 topic 1 question 25 discussion

Actual exam question from CompTIA's PT0-001
Question #: 25
Topic #: 1
[All PT0-001 Questions]

An energy company contracted a security firm to perform a penetration test of a power plant, which employs ICS to manage power generation and cooling. Which of the following is a consideration unique to such an environment that must be made by the firm when preparing for the assessment?

  • A. Selection of the appropriate set of security testing tools
  • B. Current and load ratings of the ICS components
  • C. Potential operational and safety hazards
  • D. Electrical certification of hardware used in the test
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kabwitte
Highly Voted 4 years, 9 months ago
I'm going for A. Reason? A single TCP or UDP port scan against a SCADA component can cause catastrophic damage of mass proportion. Before testing SCADA systems, pentesters should know the proper tools to use to ensure the testing provides adequate coverage and reduces the likelihood of knocking over critical services. Nutting, Raymond. CompTIA PenTest+ Certification All-in-One Exam Guide (Exam PT0-001) (p. 83). McGraw-Hill Education. Kindle Edition.
upvoted 8 times
...
[Removed]
Highly Voted 4 years, 8 months ago
For the CISSP the answer is C but this the Pentest+ the answer should be A.
upvoted 7 times
...
kloug
Most Recent 2 years, 2 months ago
ccccccccccc
upvoted 1 times
...
kloug
2 years, 2 months ago
ccccccccccccccc
upvoted 1 times
...
miabe
2 years, 9 months ago
Selected Answer: C
looks good to me
upvoted 1 times
...
brandonl
3 years, 1 month ago
A is correct because it inherently encompasses C. Choosing proper tools specifically for testing SCADA systems implies that the safety consequences of using the wrong tools has already been considered. Therefore, by choosing A, you have considered C; by choosing C, you have not necessarily considered A yet. Therefore, the answer is A in my opinion.
upvoted 1 times
...
MrRiver
3 years, 7 months ago
Just a Short Reality check: If you pentest the IT of nuclear plant what are your biggest woories? a.) Having the right tools prepared ? c:) crashing a controlling system that may contrrols the cooling pumps ? So i would go with C guy's
upvoted 6 times
...
CybeSecN
3 years, 9 months ago
The question mentioned that 'that must be made by the firm when preparing for the assessment?', so I am going for A 'Selection of the appropriate set of security testing tools'
upvoted 2 times
...
CapCrunch
3 years, 9 months ago
I have to say C safety is always first ICS covers power, gas and oil. In OT/ICS networks, both integrity and confidentiality come second to availability Industrial Control System (ICS) is an umbrella term that includes both SCADA and DCS. An ICS network can monitor many infrastructure and raw material systems. For instance, Conveyor belts in a mining operation Power consumption in the electric grid Valve pressures in a natural gas facility ICS networks are mission critical, requiring immediate and high-availability. In many ways, this emphasis represents the main difference between IT and OT/ICS systems. For IT, security is high priority preserved by the Confidentiality, Integrity, and Availability (CIA) triad. In OT/ICS networks, both integrity and confidentiality come second to availability. Source: https://www.securicon.com/whats-the-difference-between-ot-ics-scada-and-dcs/
upvoted 2 times
...
DrChats
3 years, 10 months ago
i think its C
upvoted 2 times
...
dyers
3 years, 12 months ago
I initially went with A, but after doing some searching, I'm leaning toward C: https://blog.hornecyber.com/attack-surface/rising-to-the-challenge-of-pen-testing-ics This details that we might have to coordinate scanning a PLC or other automated systems during off-hours or when no materials are in the machine, you don't want to accidentally start a machine when someone has their hands in it, for example. So you'd want to work out what those systems are and when you can scan them because of safety reasons.
upvoted 1 times
...
RedbyNight
4 years, 2 months ago
Flip a coin? For me the key word is 'unique'. as others above have said, you'd choose the right tools whatever the environment (you wouldn't want to stress test/DOS a web server. But what's unique about scada is C.
upvoted 2 times
...
TheThreatGuy
4 years, 3 months ago
I would also say that A is correct, for the same reason as kabwitte. SCADA/ICS systems are vulnerable to DoS/failure and careful consideration should be used when selecting the tools. Much more so that testing a typical windows/linux system.
upvoted 1 times
...
EZPASS
4 years, 4 months ago
I believe the correct answer is A.
upvoted 1 times
...
GreyHunter
4 years, 6 months ago
I would go for C too. Because the question said: "unique to such an environment". Answer A is not unique to this environment because in every pentest you must select the appropriate tools to be used. But for ICS you should consider operational and safety issues. Its is unique for sure.
upvoted 2 times
someguy1393
4 years, 4 months ago
That makes sense to me. My first guess would be C but I can understand how it could also be A.
upvoted 1 times
...
...
Leonar
4 years, 9 months ago
It is always human life in the first place. C !
upvoted 3 times
...
boblee
4 years, 10 months ago
The answer is A. Because you would have to more research to find tools that can test that specific scada system.
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago