CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 188


What is the PRIMARY consideration when testing industrial control systems (ICS) for security weaknesses?

Show Answer
Correct Answer: C

When testing industrial control systems (ICS) for security weaknesses, the primary consideration is that ICS are often sensitive to unexpected traffic. Industrial control systems are critical for managing and monitoring industrial processes and critical infrastructure, and they are designed to operate within specific parameters. Any unexpected network traffic or anomalies can cause these systems to malfunction or disrupt their operation, leading to serious consequences. Therefore, ensuring that security testing does not introduce unexpected traffic that could impact the integrity and functionality of ICS is crucial.

Discussion

13 comments
Sign in to comment
BoatsOption: C
Oct 2, 2022

The very fact of testing/scanning ICS devices could cause them problems. Also, they are not always hard to get to so D does not apply all the time.

jackdryan
May 13, 2023

C is correct

FiredragonOption: C
Nov 17, 2022

C. https://www.cisa.gov › recommended_practices Some ICS protocol implementations are vulnerable to packets that are malformed or contain illegal or otherwise unexpected field values.

brb77Option: C
Sep 23, 2022

question asks in the context of sec testing for sec weaknesses. in this context I'd go with C

daniecsn14Option: C
Oct 25, 2022

C is the correct

JamatiOption: C
Nov 10, 2022

C is the best answer. ICS systems can sometimes be internet facing so D is wrong.

dumdada
Jun 6, 2023

ICS systems facing the Internet? Recipe for a disaster ...

StevoooOption: D
Sep 5, 2022

Physical location/access are usually the primary concerns with ICS, SCADA systems

stickerbush1970Option: D
Sep 13, 2022

Agree with D

DJOEKOption: C
Jan 7, 2023

The primary consideration when testing industrial control systems (ICS) for security weaknesses is that ICS are often sensitive to unexpected traffic. Industrial control systems are used to control and monitor critical infrastructure and industrial processes, and disruptions to their operation can have serious consequences. Therefore, it is important to carefully consider the potential impact of any security testing on the operation of the ICS and to ensure that the testing does not disrupt or compromise the system.

SoleandheelOption: C
Dec 11, 2023

The PRIMARY consideration when testing industrial control systems (ICS) for security weaknesses is: C. ICS are often sensitive to unexpected traffic. Industrial control systems are designed to manage and control critical infrastructure and industrial processes. They are highly sensitive to unexpected or unauthorized traffic because any disruptions or unauthorized access can have serious consequences, including physical damage or safety risks. Therefore, security testing of ICS should prioritize ensuring that unexpected traffic or unauthorized access is detected and mitigated to protect the integrity and availability of these systems.

NickolosOption: D
Sep 14, 2022

Physical location/access are usually the primary concerns with ICS, SCADA systems

Nickolos
Nov 19, 2022

I was wrong. Security weakness is c. D is not a security weakness.

rdy4uOption: C
Oct 28, 2022

" ICS are often isolated and difficult to access" is not a weakness

74gjd_37Option: C
Sep 24, 2023

The primary consideration when testing industrial control systems (ICS) for security weaknesses, from a CISSP perspective, is that ICS are often sensitive to unexpected traffic. Therefore, option C is the correct answer. ICS are often designed to function within a specific set of parameters and can be easily disrupted by unexpected network traffic or activity. As such, it is critical to test and analyze ICS security measures to identify and address potential vulnerabilities before they can be exploited by malicious actors.

TheManiacOption: C
May 18, 2024

D is a common fact C is a weakness