Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A manufacturing company's operational technology (OT) network, which controls critical industrial processes, has recently been segmented from the corporate IT network. However, a security audit reveals that a single management workstation on the IT network still has direct RDP access to a critical controller on the OT network. This workstation is not subject to the same strict security controls as other OT-specific jump servers. Which security vulnerability does this scenario represent?
- ASecurity Misconfiguration
- BInsufficient Logging and Monitoring
- CBroken Access Control
- DInsecure Direct Object Reference
Show answer & explanationAnswer & explanation
Correct answer: A. Security Misconfiguration
The scenario describes a situation where a system (the management workstation) is configured in a way that creates a security weakness (direct RDP access from IT to OT without proper controls), despite segmentation efforts. This is a classic example of security misconfiguration, where security settings are incorrectly or inadequately applied.
Why the other options are wrong
- B. Insufficient Logging and Monitoring is about the absence of logs or alerts, not an active access vulnerability.
- C. Broken Access Control involves flaws in how permissions are enforced for users, not primarily system-level configuration issues.
- D. Insecure Direct Object Reference relates to direct access to internal implementation objects, not network access policies.
Security Misconfiguration
A common security vulnerability arising from improper setup or hardening of systems, applications, or networks, leading to exposed data or unauthorized access.
- Can occur at any level: OS, network devices, applications.
- Includes default configurations, open ports, unnecessary services.
- Often results from lack of security hardening or oversight.
- A top vulnerability in lists like OWASP Top 10.
Memory trick: Vulnerabilities are weak points, often due to misconfiguration or design flaws.