ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 22 - PT0-002 discussion

Report
Export

A company hired a penetration-testing team to review the cyber-physical systems in a manufacturing plant. The team immediately discovered the supervisory systems and PLCs are both connected to the company intranet. Which of the following assumptions, if made by the penetration-testing team, is MOST likely to be valid?

A.
PLCs will not act upon commands injected over the network.
Answers
A.
PLCs will not act upon commands injected over the network.
B.
Supervisors and controllers are on a separate virtual network by default.
Answers
B.
Supervisors and controllers are on a separate virtual network by default.
C.
Controllers will not validate the origin of commands.
Answers
C.
Controllers will not validate the origin of commands.
D.
Supervisory systems will detect a malicious injection of code/commands.
Answers
D.
Supervisory systems will detect a malicious injection of code/commands.
Suggested answer: C

Explanation:

PLCs are programmable logic controllers that execute logic operations on input signals from sensors and output signals to actuators. They are often connected to supervisory systems that provide human-machine interfaces and data acquisition functions. If both systems are connected to the company intranet, they are exposed to potential attacks from internal or external adversaries. A valid assumption is that controllers will not validate the origin of commands, meaning that an attacker can send malicious commands to manipulate or sabotage the industrial process. The other assumptions are not valid because they contradict the facts or common practices.

asked 02/10/2024
Delano van Kleinwee
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first