Which is the BEST deployment system for malicious code protection?
Available Choices (select all choices that are correct)
A. Network segmentation
B. IACS protocol converters
C. Application whitelistinq (AWL) OD.
D. Zones and conduits
Which of the following attacks relies on a human weakness to succeed?
Available Choices (select all choices that are correct)
A. Denial-of-service
B. Phishing
C. Escalation-of-privileges
D. Spoofing
What are the two sublayers of Layer 2?
Available Choices (select all choices that are correct)
A. HIDS and NIDS
B. LLC and MAC
C. OPC and DCOM
D. VLAN and VPN
Which organization manages the ISASecure conformance certification program?
Available Choices (select all choices that are correct)
A. American Society for Industrial Security
B. Automation Federation
C. National Institute of Standards and Technology
D. Security Compliance Institute
Which of the following is a cause for the increase in attacks on IACS?
Available Choices (select all choices that are correct)
A. Use of proprietary communications protocols
B. The move away from commercial off the shelf (COTS) systems, protocols, and networks
C. Knowledge of exploits and tools readily available on the Internet
D. Fewer personnel with system knowledge having access to IACS
Within the National Institute of Standards and Technoloqv Cybersecuritv Framework v1.0 (NIST CSF), what is the status of the ISA 62443 standards?
Available Choices (select all choices that are correct)
A. They are used as informative references.
B. They are used as normative references.
C. They are under consideration for future use.
D. They are not used.
Which service does an Intrusion Detection System (IDS) provide?
Available Choices (select all choices that are correct)
A. It is the lock on the door for networks and computer systems.
B. It is effective against all vulnerabilities in networks and computer systems.
C. It blocks malicious activity in networks and computer systems.
D. It detects attempts to break into or misuse a computer system.
Security Levels (SLs) are broken down into which three types?
Available Choices (select all choices that are correct)
A. SL-1, SL-2, and SL-3
B. Target.capability, and achieved
C. Target.capability, and availability
D. Target.capacity, and achieved
In an IACS system, a typical security conduit consists of which of the following assets?
Available Choices (select all choices that are correct)
A. Controllers, sensors, transmitters, and final control elements
B. Wiring, routers, switches, and network management devices
C. Ferrous, thickwall, and threaded conduit including raceways
D. Power lines, cabinet enclosures, and protective grounds
After receiving an approved patch from the JACS vendor, what is BEST practice for the asset owner to follow?
A. If a low priority, there is no need to apply the patch.
B. If a medium priority, schedule the installation within three months after receipt.
C. If a high priority, apply the patch at the first unscheduled outage.
D. If no problems are experienced with the current IACS, it is not necessary to apply the patch.