CySA Section 6 Critical Infrastructure Concepts

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/71

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:46 PM on 9/22/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

72 Terms

1
New cards

Critical infrastructure

the collection of systems, assets, and networks so essential to national security, public health, and economic stability that their disruption would have severe consequences

2
New cards

CISA identifies _ official critical infrastructure sectors

16

3
New cards

Most exam-relevant critical infrastructure sectors

energy, water and wastewater, healthcare, financial services, and transportation

4
New cards

Most critical infrastructure in the United States is owned and operated by private companies, placing _____ on the front lines of defense

private-sector SOC analysts

5
New cards

Information Sharing and Analysis Centers (ISACs)

sector-specific organizations where member companies share threat intelligence and defensive best practices

6
New cards

Key ISACs

E-ISAC (electricity), H-ISAC (healthcare), and FS-ISAC (financial services)

7
New cards

In OT and critical infrastructure environments, the CIA triad priority order flips to..

AIC; availability comes first because downtime has physical consequences

8
New cards

MITRE ATT&CK for ICS

extends the standard framework to map adversary tactics and techniques specific to industrial control system environments

9
New cards

Operational Technology (OT)

the hardware and software that monitors and controls physical devices and processes in the real world. IT processes data. This controls things

10
New cards

Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers:_____, PLCs, HMIs, control servers, data historians, and the enterprise IT network

field devices (sensors, actuators)

11
New cards

Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), ____, HMIs, control servers, data historians, and the enterprise IT network

PLCs

12
New cards

Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), PLCs, HMIs, control servers, data historians, and the enterprise IT network

13
New cards

Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), PLCs, ____, control servers, data historians, and the enterprise IT network

HMIs

14
New cards

Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), PLCs, HMIs,____, data historians, and the enterprise IT network

control servers

15
New cards

Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), PLCs, HMIs, control servers, ____, and the enterprise IT network

data historians

16
New cards

Purdue Model (Purdue Enterprise Reference Architecture) describes OT in layers: field devices (sensors, actuators), PLCs, HMIs, control servers, data historians, and _____

the enterprise IT network

17
New cards

Programmable Logic Controllers (PLCs)

specialized industrial computers that run continuous sense-compare-act control loops. They have minimal logging capability compared to IT systems.

18
New cards

Human-Machine Interfaces (HMIs)

operator control panels or software on Windows workstations. These running on Windows are IT systems tightly coupled to OT processes and often run unpatched legacy operating systems

19
New cards

data historian

a time-series database storing all operational process data and is a key forensic resource during OT incident investigations

20
New cards

The ____ assumption is largely gone. IT/OT convergence has connected OT networks to corporate IT, dramatically expanding the OT attack surface.

air gap

21
New cards

Industrial Control System (ICS)

the specific OT category that automates and coordinates industrial processes using PLCs, control servers, HMIs, and data historians

22
New cards

Distributed Control System (DCS)

manages process automation within a single site

23
New cards

ICS protocols including Modbus and DNP3 were not designed with ____

security as a primary goal; Modbus has no authentication nor encryption

24
New cards

Active scanning is typically…

prohibited in ICS environments because unexpected network traffic can crash PLCs and control systems

25
New cards

OT-aware monitoring tool examples

Dragos, Nozomi Networks, Claroty

26
New cards

OT-aware monitoring tool are required because

standard IT security tools do not understand industrial protocols like Modbus and DNP3

27
New cards

Historian data can be correlated with…

network logs to identify process anomalies and build an incident timeline, serving as the OT equivalent of SIEM log correlation

28
New cards

When a scenario presents an HMI on an unpatched Windows system, the correct response is..

compensating controls (network segmentation, application whitelisting, enhanced monitoring)

29
New cards

SCADA (Supervisory Control and Data Acquisition)

a large-scale ICS that manages physical processes across multiple geographically distributed sites over wide-area networks

30
New cards

SCADA architecture: _____; Remote Terminal Units (RTUs) at each field site communicate back over WAN links

central SCADA server (Master Terminal Unit, or MTU) sends supervisory commands

31
New cards

SCADA architecture: central SCADA server (Master Terminal Unit, or MTU) sends supervisory commands;_____

Remote Terminal Units (RTUs) at each field site communicate back over WAN links

32
New cards

In a SCADA architecture, HMIs provide…

operator visibility

33
New cards

The shift from serial/radio WAN links to IP-based cellular and internet communications dramatically expanded _____

the SCADA attack surface

34
New cards

SCADA HMIs often run _______ due to SCADA software vendor compatibility constraints. This is an operational limitation, not negligence

legacy operating systems (Windows 7, Windows XP)

35
New cards

______ (discovered 2010) is the defining SCADA attack: it manipulated centrifuge speed control logic while sending false normal readings to the HMI, causing physical destruction without operator awareness.

Stuxnet

36
New cards

Process value spoofing

a key SCADA attack technique where sensor readings are falsified while the physical process is being manipulated.

37
New cards

If a scenario shows normal SCADA readings alongside abnormal physical equipment behavior, the correct analytical conclusion is

potential process value spoofing by an attacker

38
New cards

For SCADA WAN links, absence of ______, encryption, and certificate-based authentication is a critical vulnerability finding

VPN tunnels

39
New cards

For SCADA WAN links, absence of VPN tunnels, _____, and certificate-based authentication is a critical vulnerability finding

encryption

40
New cards

For SCADA WAN links, absence of VPN tunnels, encryption, and ______ is a critical vulnerability finding

certificate-based authentication

41
New cards

Nation-state actors

target critical infrastructure for pre-positioning

42
New cards

pre-positioning

gaining persistent access to cause disruption at a time of their choosing, not necessarily for immediate action

43
New cards

Primary attack vectors

lateral movement from IT to OT networks through an insufficiently protected IT/OT boundary, and exploitation of insecure remote access (exposed RDP, unencrypted VPN, insecure remote access software)

44
New cards

Living-off-the-land in OT

means using legitimate industrial protocols (Modbus write commands) to blend into normal traffic. Detection must be behavioral, not signaturebased.

45
New cards

Key OT indicators of compromise:_____, unexpected PLC write commands (normal OT traffic is mostly read/poll traffic), process value anomalies deviating from historical baselines, and HMI login anomalies

rogue devices on the OT network

46
New cards

Key OT indicators of compromise: rogue devices on the OT network, _______, process value anomalies deviating from historical baselines, and HMI login anomalies

unexpected PLC write commands (normal OT traffic is mostly read/poll traffic)

47
New cards

Key OT indicators of compromise: rogue devices on the OT network, unexpected PLC write commands (normal OT traffic is mostly read/poll traffic), _____, and HMI login anomalies

process value anomalies deviating from historical baselines

48
New cards

Key OT indicators of compromise: rogue devices on the OT network, unexpected PLC write commands (normal OT traffic is mostly read/poll traffic), process value anomalies deviating from historical baselines, and _____

HMI login anomalies

49
New cards

OT incident response require

coordination with operations teams

50
New cards

Isolating a device or blocking a connection without operations coordination can cause

uncontrolled process shutdowns more dangerous than the attack itself

51
New cards

MITRE ATT&CK for ICS key tactics: ______, Impair Process Control (manipulating control logic), and Impact (physical damage)

Inhibit Response Function (preventing safety systems from operating)

52
New cards

MITRE ATT&CK for ICS key tactics: Inhibit Response Function (preventing safety systems from operating),______, and Impact (physical damage)

Impair Process Control (manipulating control logic)

53
New cards

MITRE ATT&CK for ICS key tactics: Inhibit Response Function (preventing safety systems from operating), Impair Process Control (manipulating control logic), and _____

Impact (physical damage)

54
New cards

When a scenario asks what to do upon detecting a threat in an OT environment, the correct answer involves

notifying operations and using compensating controls, not immediately isolating devices

55
New cards

Any IT system communicating directly with PLCs or SCADA servers without an approved communication path is a

high-priority alert

56
New cards

Industrial DMZ (IDMZ

the gold-standard segmentation architecture: all IT/OT communication passes through a controlled zone. No direct connections from the corporate network to PLCs or control systems

57
New cards

Data diodes

Hardware devices that enforce one-way data flow, allowing OT data to reach IT for reporting while blocking any command path back into OT

58
New cards

Compensating controls for unpatched OT systems include _____, network isolation, and host-based firewalls. These replace patching when patching is not feasible

application whitelisting (restricts HMIs to approved executables only)

59
New cards

Compensating controls for unpatched OT systems include application whitelisting (restricts HMIs to approved executables only), _____, and host-based firewalls. These replace patching when patching is not feasible

network isolation

60
New cards

Compensating controls for unpatched OT systems include application whitelisting (restricts HMIs to approved executables only), network isolation, and ______. These replace patching when patching is not feasible

host-based firewalls

61
New cards

Passive monitoring tools examples

Dragos Platform, Nozomi Networks Guardian, Claroty

62
New cards

Passive monitoring tools provide OT visibility by

observing traffic without sending active probes. Active scanning can crash PLCs

63
New cards

All remote access to OT must ____, session logging, and time-limited vendor access

route through a dedicated jump server or bastion host in the IDMZ with MFA

64
New cards

All remote access to OT must route through a dedicated jump server or bastion host in the IDMZ with MFA,____, and time-limited vendor access

session logging

65
New cards

All remote access to OT must route through a dedicated jump server or bastion host in the IDMZ with MFA, session logging, and _____

time-limited vendor access

66
New cards

Safety Instrumented Systems (SIS)

independent safety systems that shut down processes when parameters exceed safe limits

67
New cards

Attacks targeting SIS (MITRE ATT&CK for ICS: Inhibit Response Function) are the highest

severity OT incidents

68
New cards

NIST SP 800-82

The primary NIST reference for OT security

69
New cards

IEC 62443

the international standard for industrial cybersecurity

70
New cards

When a scenario presents an OT system that cannot be patched, the correct answer is

compensating controls (application whitelisting, network isolation, monitoring), never "apply patches immediately."

71
New cards

A scenario involving a Safety Instrumented System being targeted or bypassed is an

extreme high-severity incident requiring immediate escalation to both security and safety engineering teams

72
New cards