SY0-701 exam dumps

SY0-701 practice question 177 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 177

Single answerIndustrial control systems (ICS)/supervisory control and data acquisition (SCADA)

A power generation company is connecting a legacy SCADA environment to the corporate network so engineers can review process data from headquarters. During a risk assessment, the security team discovers that several PLCs and HMIs use older protocols that do not support encryption or strong authentication, and plant leadership warns that unplanned downtime is unacceptable. Which of the following is the BEST way to reduce cybersecurity risk while preserving operational availability?

  1. A

    Place the SCADA network on a separate, tightly controlled network segment behind an industrial DMZ and allow only required communications through firewalls

  2. B

    Deploy endpoint detection and response agents directly on all PLCs and RTUs so malicious activity can be blocked at the device level

  3. C

    Join all SCADA servers, HMIs, PLCs, and field devices to the corporate Active Directory domain to centralize authentication

  4. D

    Schedule immediate patching and firmware upgrades for all PLCs and HMIs during business hours to eliminate legacy protocol exposure

Show answer and explanation

Correct answer: A

Explanation

The best answer is to isolate the SCADA environment using network segmentation and an industrial DMZ. In ICS/SCADA environments, many devices rely on legacy protocols such as Modbus or DNP3 variants that may lack native encryption and authentication. Because these systems often have strict uptime and safety requirements, organizations commonly use compensating controls rather than making disruptive changes directly on control devices. Network zoning, traffic allowlisting, and an ICS-specific DMZ are widely recommended in guidance such as NIST SP 800-82, Guide to Operational Technology (OT) Security, and ISA/IEC 62443. These practices help separate enterprise IT from OT, reduce lateral movement risk, and preserve operational availability while still enabling necessary business access.

  • A. Correct.

    This is the best answer because segmentation is a primary security control for ICS/SCADA environments, especially when legacy protocols cannot be hardened with modern encryption or authentication. Using a dedicated ICS network and an industrial DMZ limits exposure from the corporate network while allowing only specific, necessary traffic flows. This approach aligns with common guidance for ICS security because it reduces the attack surface without requiring disruptive changes to fragile control devices.

  • B. Incorrect.

    This is incorrect because many PLCs and RTUs do not support traditional endpoint security agents, and installing such software can affect safety, stability, vendor support, or deterministic performance. In ICS environments, controls are often applied around devices rather than directly on them. Someone might choose this option because EDR is a strong control in IT systems, but it is often impractical or unsupported in operational technology.

  • C. Incorrect.

    This is incorrect because extending the corporate domain broadly into the control environment increases trust relationships and can expand the blast radius of a compromise. While centralized identity may be appropriate for some ICS Windows-based systems under careful design, joining all control components, especially PLCs and field devices, is neither realistic nor a best-practice risk reduction strategy. This reflects a common misconception that IT identity practices can be applied wholesale to OT environments.

  • D. Incorrect.

    This is incorrect because immediate patching during business hours conflicts with the requirement to avoid unplanned downtime and ignores the fact that ICS patching typically requires testing, maintenance windows, and vendor validation. Patching is important, but it is not the best immediate control in this scenario. A candidate might choose this because patching is generally recommended in IT, but ICS prioritizes safety and availability, so compensating controls such as segmentation are often used first.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam