Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A manufacturing company's operational technology (OT) network, which controls critical industrial processes, has recently been segmented from the corporate IT network. However, a security audit reveals that a single management workstation on the IT network still has direct RDP access to a critical controller on the OT network. This workstation is not subject to the same strict security controls as other OT-specific jump servers. Which security vulnerability does this scenario represent?

  1. ASecurity Misconfiguration
  2. BInsufficient Logging and Monitoring
  3. CBroken Access Control
  4. DInsecure Direct Object Reference
Show answer & explanation

Correct answer: A. Security Misconfiguration

The scenario describes a situation where a system (the management workstation) is configured in a way that creates a security weakness (direct RDP access from IT to OT without proper controls), despite segmentation efforts. This is a classic example of security misconfiguration, where security settings are incorrectly or inadequately applied.

Why the other options are wrong

  • B. Insufficient Logging and Monitoring is about the absence of logs or alerts, not an active access vulnerability.
  • C. Broken Access Control involves flaws in how permissions are enforced for users, not primarily system-level configuration issues.
  • D. Insecure Direct Object Reference relates to direct access to internal implementation objects, not network access policies.

Security Misconfiguration

A common security vulnerability arising from improper setup or hardening of systems, applications, or networks, leading to exposed data or unauthorized access.

  • Can occur at any level: OS, network devices, applications.
  • Includes default configurations, open ports, unnecessary services.
  • Often results from lack of security hardening or oversight.
  • A top vulnerability in lists like OWASP Top 10.

Memory trick: Vulnerabilities are weak points, often due to misconfiguration or design flaws.

More Security Concepts questions