CompTIA SecurityX (CAS-005)Security EngineeringHard

A critical infrastructure organization is implementing a new Industrial Control System (ICS) for its power grid. Due to the high-impact nature of potential cyberattacks, the security architect must ensure the system adheres to the 'defense-in-depth' principle. Which of the following security measures, when applied to the ICS, BEST exemplifies this principle?

  1. AUtilizing a demilitarized zone (DMZ) to segment the ICS network from the enterprise network, alongside network segmentation within the ICS, host-based firewalls, and application whitelisting on controllers.
  2. BImplementing a single, robust firewall at the perimeter of the ICS network.
  3. CEnforcing strong password policies and multi-factor authentication (MFA) for all ICS operator accounts.
  4. DDeploying an Intrusion Detection System (IDS) to monitor all traffic within the ICS network for anomalies.
Show answer & explanation

Correct answer: A. Utilizing a demilitarized zone (DMZ) to segment the ICS network from the enterprise network, alongside network segmentation within the ICS, host-based firewalls, and application whitelisting on controllers.

Defense-in-depth involves multiple layers of security controls to protect critical assets. Option B describes a multi-layered approach including network segmentation (DMZ, internal segmentation), host-based controls (firewalls), and application-level controls (whitelisting), which is a strong embodiment of this principle for ICS.

Why the other options are wrong

  • B. A single firewall is a single point of failure and does not represent multiple layers of defense.
  • C. Strong authentication is a critical security control, but it's a single layer focused on access, not a comprehensive defense-in-depth strategy for the entire system.
  • D. An IDS is an important monitoring tool, but it's one layer of defense and primarily reactive, not a comprehensive multi-layered prevention strategy.

Defense-in-Depth

A security strategy that employs multiple layers of security controls to protect assets, so if one control fails, others are still in place.

  • Layered security approach.
  • Reduces reliance on a single security control.
  • Applies to physical, technical, and administrative controls.

Memory trick: Layers of defense, like an onion, protect the core.

More Security Engineering questions