CompTIA CySA+ (CS0-003)Security OperationsHard
A security analyst is reviewing network traffic on a segment hosting critical industrial control systems (ICS). The analyst notices a significant amount of Modbus/TCP traffic originating from an unauthorized IT workstation (192.168.10.50) attempting to communicate with a Programmable Logic Controller (PLC) (172.16.1.10) on port 502. The IT workstation should not be initiating direct communication with the PLC. What is the most critical security concern presented by this activity in an OT/ICS environment?
- ACredential Theft
- BDenial of Service (DoS)
- CUnauthorized Control/Manipulation
- DData Exfiltration
Show answer & explanationAnswer & explanation
Correct answer: C. Unauthorized Control/Manipulation
In an OT/ICS environment, unauthorized Modbus/TCP communication directly to a PLC is a critical concern because it indicates an attempt to establish unauthorized control or manipulation of the industrial process. Modbus/TCP is a protocol used for reading and writing data to PLCs, and an unauthorized workstation attempting this suggests a direct threat to the operational integrity and safety of the physical process.
Why the other options are wrong
- A. Credential theft might be a precursor to this, but the observed activity itself is direct control communication, not credential theft.
- B. DoS is a possibility, but direct Modbus/TCP to a PLC is more specific to *control* rather than just disruption. Manipulation could lead to a DoS but the intent is deeper.
- D. While data exfiltration could be a secondary concern, direct Modbus/TCP communication to a PLC primarily indicates an attempt to control or manipulate the system, which is far more critical in OT.
OT/ICS Security Considerations
Security considerations unique to Operational Technology (OT) and Industrial Control Systems (ICS) environments, prioritizing safety, availability, and integrity of physical processes.
- Safety and availability often outweigh confidentiality.
- Common protocols: Modbus, DNP3, OPC, EtherNet/IP.
- Unauthorized access can lead to physical damage, environmental harm, or loss of life.
Memory trick: ICS attacks prioritize physical harm and control.