1/71
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Critical infrastructure
the collection of systems, assets, and networks so essential to national security, public health, and economic stability that their disruption would have severe consequences
CISA identifies _ official critical infrastructure sectors
16
Most exam-relevant critical infrastructure sectors
energy, water and wastewater, healthcare, financial services, and transportation
Most critical infrastructure in the United States is owned and operated by private companies, placing _____ on the front lines of defense
private-sector SOC analysts
Information Sharing and Analysis Centers (ISACs)
sector-specific organizations where member companies share threat intelligence and defensive best practices
Key ISACs
E-ISAC (electricity), H-ISAC (healthcare), and FS-ISAC (financial services)
In OT and critical infrastructure environments, the CIA triad priority order flips to..
AIC; availability comes first because downtime has physical consequences
MITRE ATT&CK for ICS
extends the standard framework to map adversary tactics and techniques specific to industrial control system environments
Operational Technology (OT)
the hardware and software that monitors and controls physical devices and processes in the real world. IT processes data. This controls things
Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers:_____, PLCs, HMIs, control servers, data historians, and the enterprise IT network
field devices (sensors, actuators)
Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), ____, HMIs, control servers, data historians, and the enterprise IT network
PLCs
Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), PLCs, HMIs, control servers, data historians, and the enterprise IT network
Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), PLCs, ____, control servers, data historians, and the enterprise IT network
HMIs
Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), PLCs, HMIs,____, data historians, and the enterprise IT network
control servers
Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), PLCs, HMIs, control servers, ____, and the enterprise IT network
data historians
Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), PLCs, HMIs, control servers, data historians, and _____
the enterprise IT network
Programmable Logic Controllers (PLCs)
specialized industrial computers that run continuous sense-compare-act control loops. They have minimal logging capability compared to IT systems.
Human-Machine Interfaces (HMIs)
operator control panels or software on Windows workstations. These running on Windows are IT systems tightly coupled to OT processes and often run unpatched legacy operating systems
data historian
a time-series database storing all operational process data and is a key forensic resource during OT incident investigations
The ____ assumption is largely gone. IT/OT convergence has connected OT networks to corporate IT, dramatically expanding the OT attack surface.
air gap
Industrial Control System (ICS)
the specific OT category that automates and coordinates industrial processes using PLCs, control servers, HMIs, and data historians
Distributed Control System (DCS)
manages process automation within a single site
ICS protocols including Modbus and DNP3 were not designed with ____
security as a primary goal; Modbus has no authentication nor encryption
Active scanning is typically…
prohibited in ICS environments because unexpected network traffic can crash PLCs and control systems
OT-aware monitoring tool examples
Dragos, Nozomi Networks, Claroty
OT-aware monitoring tool are required because
standard IT security tools do not understand industrial protocols like Modbus and DNP3
Historian data can be correlated with…
network logs to identify process anomalies and build an incident timeline, serving as the OT equivalent of SIEM log correlation
When a scenario presents an HMI on an unpatched Windows system, the correct response is..
compensating controls (network segmentation, application whitelisting, enhanced monitoring)
SCADA (Supervisory Control and Data Acquisition)
a large-scale ICS that manages physical processes across multiple geographically distributed sites over wide-area networks
SCADA architecture: _____; Remote Terminal Units (RTUs) at each field site communicate back over WAN links
central SCADA server (Master Terminal Unit, or MTU) sends supervisory commands
SCADA architecture: central SCADA server (Master Terminal Unit, or MTU) sends supervisory commands;_____
Remote Terminal Units (RTUs) at each field site communicate back over WAN links
In a SCADA architecture, HMIs provide…
operator visibility
The shift from serial/radio WAN links to IP-based cellular and internet communications dramatically expanded _____
the SCADA attack surface
SCADA HMIs often run _______ due to SCADA software vendor compatibility constraints. This is an operational limitation, not negligence
legacy operating systems (Windows 7, Windows XP)
______ (discovered 2010) is the defining SCADA attack: it manipulated centrifuge speed control logic while sending false normal readings to the HMI, causing physical destruction without operator awareness.
Stuxnet
Process value spoofing
a key SCADA attack technique where sensor readings are falsified while the physical process is being manipulated.
If a scenario shows normal SCADA readings alongside abnormal physical equipment behavior, the correct analytical conclusion is
potential process value spoofing by an attacker
For SCADA WAN links, absence of ______, encryption, and certificate-based authentication is a critical vulnerability finding
VPN tunnels
For SCADA WAN links, absence of VPN tunnels, _____, and certificate-based authentication is a critical vulnerability finding
encryption
For SCADA WAN links, absence of VPN tunnels, encryption, and ______ is a critical vulnerability finding
certificate-based authentication
Nation-state actors
target critical infrastructure for pre-positioning
pre-positioning
gaining persistent access to cause disruption at a time of their choosing, not necessarily for immediate action
Primary attack vectors
lateral movement from IT to OT networks through an insufficiently protected IT/OT boundary, and exploitation of insecure remote access (exposed RDP, unencrypted VPN, insecure remote access software)
Living-off-the-land in OT
means using legitimate industrial protocols (Modbus write commands) to blend into normal traffic. Detection must be behavioral, not signaturebased.
Key OT indicators of compromise:_____, unexpected PLC write commands (normal OT traffic is mostly read/poll traffic), process value anomalies deviating from historical baselines, and HMI login anomalies
rogue devices on the OT network
Key OT indicators of compromise: rogue devices on the OT network, _______, process value anomalies deviating from historical baselines, and HMI login anomalies
unexpected PLC write commands (normal OT traffic is mostly read/poll traffic)
Key OT indicators of compromise: rogue devices on the OT network, unexpected PLC write commands (normal OT traffic is mostly read/poll traffic), _____, and HMI login anomalies
process value anomalies deviating from historical baselines
Key OT indicators of compromise: rogue devices on the OT network, unexpected PLC write commands (normal OT traffic is mostly read/poll traffic), process value anomalies deviating from historical baselines, and _____
HMI login anomalies
OT incident response require
coordination with operations teams
Isolating a device or blocking a connection without operations coordination can cause
uncontrolled process shutdowns more dangerous than the attack itself
MITRE ATT&CK for ICS key tactics: ______, Impair Process Control (manipulating control logic), and Impact (physical damage)
Inhibit Response Function (preventing safety systems from operating)
MITRE ATT&CK for ICS key tactics: Inhibit Response Function (preventing safety systems from operating),______, and Impact (physical damage)
Impair Process Control (manipulating control logic)
MITRE ATT&CK for ICS key tactics: Inhibit Response Function (preventing safety systems from operating), Impair Process Control (manipulating control logic), and _____
Impact (physical damage)
When a scenario asks what to do upon detecting a threat in an OT environment, the correct answer involves
notifying operations and using compensating controls, not immediately isolating devices
Any IT system communicating directly with PLCs or SCADA servers without an approved communication path is a
high-priority alert
Industrial DMZ (IDMZ
the gold-standard segmentation architecture: all IT/OT communication passes through a controlled zone. No direct connections from the corporate network to PLCs or control systems
Data diodes
Hardware devices that enforce one-way data flow, allowing OT data to reach IT for reporting while blocking any command path back into OT
Compensating controls for unpatched OT systems include _____, network isolation, and host-based firewalls. These replace patching when patching is not feasible
application whitelisting (restricts HMIs to approved executables only)
Compensating controls for unpatched OT systems include application whitelisting (restricts HMIs to approved executables only), _____, and host-based firewalls. These replace patching when patching is not feasible
network isolation
Compensating controls for unpatched OT systems include application whitelisting (restricts HMIs to approved executables only), network isolation, and ______. These replace patching when patching is not feasible
host-based firewalls
Passive monitoring tools examples
Dragos Platform, Nozomi Networks Guardian, Claroty
Passive monitoring tools provide OT visibility by
observing traffic without sending active probes. Active scanning can crash PLCs
All remote access to OT must ____, session logging, and time-limited vendor access
route through a dedicated jump server or bastion host in the IDMZ with MFA
All remote access to OT must route through a dedicated jump server or bastion host in the IDMZ with MFA,____, and time-limited vendor access
session logging
All remote access to OT must route through a dedicated jump server or bastion host in the IDMZ with MFA, session logging, and _____
time-limited vendor access
Safety Instrumented Systems (SIS)
independent safety systems that shut down processes when parameters exceed safe limits
Attacks targeting SIS (MITRE ATT&CK for ICS: Inhibit Response Function) are the highest
severity OT incidents
NIST SP 800-82
The primary NIST reference for OT security
IEC 62443
the international standard for industrial cybersecurity
When a scenario presents an OT system that cannot be patched, the correct answer is
compensating controls (application whitelisting, network isolation, monitoring), never "apply patches immediately."
A scenario involving a Safety Instrumented System being targeted or bypassed is an
extreme high-severity incident requiring immediate escalation to both security and safety engineering teams