Which characteristic is MOST closely associated with the deployment of a demilitarized zone (DMZ)?
Available Choices (select all choices that are correct)
A. Level 4 systems must use the DMZ to communicate with Level 3 and below.
B. Level 0 can only interact with Level 1 through the firewall.
C. Internet access through the firewall is allowed.
D. Email is prevented, thereby mitigating the risk of phishing attempts.
Which statement is TRUE reqardinq application of patches in an IACS environment?
Available Choices (select all choices that are correct)
A. Patches should be applied as soon as they are available.
B. Patches should be applied within one month of availability.
C. Patches never should be applied in an IACS environment.
D. Patches should be applied based on the organization's risk assessment.
What are the connections between security zones called?
Available Choices (select all choices that are correct)
A. Firewalls
B. Tunnels
C. Pathways
D. Conduits
Which is the PRIMARY objective when defining a security zone?
Available Choices (select all choices that are correct)
A. All assets in the zone must be from the same vendor.
B. All assets in the zone must share the same security requirements.
C. All assets in the zone must be at the same level in the Purdue model.
D. All assets in the zone must be physically located in the same area.
Which communications system covers a large geographic area?
Available Choices (select all choices that are correct)
A. Campus Area Network (CAN)
B. Local Area Network (LAN)
C. Storage Area Network
D. Wide Area Network (WAN)
Which is the PRIMARY responsibility of the network layer of the Open Systems Interconnection (OSI) model?
Available Choices (select all choices that are correct)
A. Forwards packets, including routing through intermediate routers
B. Gives transparent transfer of data between end users
C. Provides the rules for framing, converting electrical signals to data
D. Handles the physics of getting a message from one device to another
Which is a PRIMARY reason why network security is important in IACS environments?
Available Choices (select all choices that are correct)
A. PLCs are inherently unreliable.
B. PLCs are programmed using ladder logic.
C. PLCs use serial or Ethernet communications methods.
D. PLCs under cyber attack can have costly and dangerous impacts.
Authorization (user accounts) must be granted based on which of the following?
Available Choices (select all choices that are correct)
A. Individual preferences
B. Common needs for large groups
C. Specific roles
D. System complexity
Which factor drives the selection of countermeasures?
Available Choices (select all choices that are correct)
A. Foundational requirements
B. Output from a risk assessment
C. Security levels
D. System design
After receiving an approved patch from the JACS vendor, what is BEST practice for the asset owner to follow?
A. If a low priority, there is no need to apply the patch.
B. If a medium priority, schedule the installation within three months after receipt.
C. If a high priority, apply the patch at the first unscheduled outage.
D. If no problems are experienced with the current IACS, it is not necessary to apply the patch.