Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 317 discussion

Actual exam question from ISC's CISSP
Question #: 317
Topic #: 1
[All CISSP Questions]

When designing a Cyber-Physical System (CPS), which of the following should be a security practitioner's first consideration?

  • A. Detection of sophisticated attackers
  • B. Topology of the network used for the system
  • C. Risk assessment of the system
  • D. Resiliency of the system
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Humongous1593
Highly Voted 2 years, 1 month ago
Selected Answer: D
Talking about systems that could affect human life. Needs resiliency.
upvoted 7 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 1 times
...
...
CCNPWILL
Most Recent 5 months, 3 weeks ago
Selected Answer: C
Correct Answer is indeed C. Doing the risk assessment you will find that we need resiliency.
upvoted 1 times
...
eboehm
7 months, 2 weeks ago
Selected Answer: C
Sooo many people jumping to D when C is all encompassing. Did everyone skip domain 1 or something? EVERYTHING always starts with risk
upvoted 2 times
...
gjimenezf
10 months ago
Selected Answer: C
Risk assessment will find as a risk the resiliency aspect
upvoted 1 times
...
YesPlease
11 months, 1 week ago
Selected Answer: C
Answer C) Risk assessment of the system A risk assessment will include all of the other answers. Wrong Answers: A. Detection of sophisticated attackers B. Topology of the network used for the system D. Resiliency of the system
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
C. Risk assessment of the system Conducting a thorough risk assessment is a fundamental step in designing the security for any system, including CPS. Conducting a risk assessment covers all the other answer options which makes it the best answer.
upvoted 1 times
...
DapengZhang
12 months ago
Selected Answer: C
C, C includes B. Risk management covers the resiliency design.
upvoted 1 times
...
InclusiveSTEAM
1 year, 1 month ago
The answer is C: The first consideration when designing a cyber-physical system (CPS) security should be performing a risk assessment of the system, option C. Conducting a risk assessment provides the essential foundation to understand potential vulnerabilities, threats, and impacts to the CPS. This informs requirements and controls. While attacker detection, network topology, and resilience are important, they should stem from knowledge gained through the initial risk analysis. Without assessing risk first, the priorities and tradeoffs for subsequent activities like monitoring sophisticated attackers, designing secure network topology, and engineering resilient components cannot be contextualized properly. Therefore, a risk assessment provides the crucial first step that underpins effective cybersecurity design for CPS by identifying what needs protection and possible consequences.
upvoted 1 times
...
Dam0s
1 year, 1 month ago
Selected Answer: C
Resiliency of the system (Option D): Resiliency is important, but it's often addressed after conducting a risk assessment. The risk assessment informs decisions about how to design the system to be resilient against specific threats.
upvoted 1 times
...
BoyBastos
1 year, 2 months ago
Selected Answer: C
C. Risk assessment of the system When designing a Cyber-Physical System (CPS) or any system, the first consideration for a security practitioner should be a risk assessment. By conducting a risk assessment, the practitioner can identify potential threats, vulnerabilities, and the potential impact of those threats. This assessment forms the foundation for all subsequent security decisions, including detection mechanisms, network topology considerations, and system resiliency measures. Understanding the risks allows for informed decisions about where to allocate resources and which security measures to prioritize.
upvoted 2 times
...
HughJassole
1 year, 5 months ago
A. The question is asking about a security professional's concerns during development of this system. Seems like " Detection of sophisticated attackers" is the only option that has to do directly with security. On this topic, I read books about how IoT devices are not secure at all, in fact when Dick Cheney had his pacemaker installed the wireless transmitter was removed so that he can't be injured by a hacker. Hackers have taken over baby monitors. Seems like with such a critical system that will control your life finding sophisticated attackers is the top priority.
upvoted 1 times
HughJassole
1 year, 4 months ago
I am changing my response to D: "We always need to begin with a risk assessment of a given environment or given device or a given application." https://cloudacademy.com/course/cissp-domain-3-security-architecture-engineering-module-6/assess-and-mitigate-vulnerabilities-embedded-devices-and-cyber-physical-systems/
upvoted 1 times
SSimko
10 months, 1 week ago
Don't you mean C and not D in that case?
upvoted 1 times
...
...
...
ACunningPlan
1 year, 7 months ago
Selected Answer: C
Resiliency won't matter if you have done proper risk assessment.
upvoted 4 times
ACunningPlan
1 year, 7 months ago
..."haven't" done proper risk assessment.
upvoted 1 times
...
...
MarkSun
1 year, 8 months ago
Selected Answer: D
CPS are often used in safety-critical applications where a failure could result in harm to people or damage to property. Therefore, ensuring the safety and reliability of these systems is of utmost importance.
upvoted 1 times
...
Rollingalx
1 year, 9 months ago
I vote for C While resiliency is an important consideration, it is not the first consideration that a security practitioner should make when designing a CPS. Before considering resiliency, it is important to conduct a risk assessment of the system to identify potential security risks and vulnerabilities. This information can then be used to determine the appropriate security controls and countermeasures needed to protect the system, including measures to enhance its resiliency.
upvoted 3 times
...
CuteRabbit168
2 years, 1 month ago
Selected Answer: D
Answer is correct
upvoted 3 times
...
Cww1
2 years, 2 months ago
I think this is B, you want to segment iot devices
upvoted 1 times
...
jon1991
2 years, 2 months ago
Cyber-physical systems refer to devices that offer a computational means to control something in the physical world. Examples of cyber-physical systems are embedded systems, and network-enabled devices is that of the Internet of Things (IoT) And for examples it include prosthetics to provide human augmentation or assistance, collision avoidance in vehicles, air traffic control coordination, precision in robot surgery, remote operation in hazardous conditions, and energy conservation in vehicles, equipment, mobile devices, and buildings.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...