Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium
A critical infrastructure organization (CIO) manages operational technology (OT) systems that control power grids and water treatment facilities. These systems are highly sensitive, often legacy, and have strict uptime requirements, making traditional IT security patching and scanning methods impractical. The cybersecurity architect needs to implement a security operations strategy that monitors for threats, detects anomalies specific to OT protocols, and facilitates a rapid, but highly controlled, response without disrupting operations. Which strategy is MOST appropriate?
- AUtilizing a comprehensive Endpoint Detection and Response (EDR) solution on all OT devices.
- BEstablishing a robust Vulnerability Management (VM) program with weekly active scanning.
- CImplementing a standard IT Security Information and Event Management (SIEM) system.
- DDeploying an OT-specific Intrusion Detection System (IDS) integrated with a specialized OT Security Operations Center (SOC).
Show answer & explanationAnswer & explanation
Correct answer: D. Deploying an OT-specific Intrusion Detection System (IDS) integrated with a specialized OT Security Operations Center (SOC).
An OT-specific IDS can monitor unique OT protocols for anomalies and threats without impacting operations, and integration with a specialized OT SOC ensures that responses are tailored to the sensitive nature of OT environments.
Why the other options are wrong
- A. Deploying EDR on legacy OT systems is often impossible due to system compatibility issues, performance impact, and vendor support limitations.
- B. Weekly active scanning for vulnerabilities is highly disruptive and dangerous in live OT environments, which prioritize uptime and stability over frequent changes.
- C. Standard IT SIEMs often lack visibility into specialized OT protocols and may generate excessive false positives or miss critical OT threats.
OT Security Operations Center (OT SOC)
An OT SOC is a specialized security operations center focused on monitoring, detecting, and responding to threats within industrial control systems and operational technology environments.
- Understands unique OT protocols and vulnerabilities.
- Prioritizes system uptime and safety.
- Integrates with OT-specific security tools (e.g., OT IDS/IPS).
Memory trick: An OT SOC is the 'Industrial Watchdog' for 'Critical Operations'.