SY0-701 exam dumps

SY0-701 practice question 178 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 178

Single answerIndustrial control systems (ICS)/supervisory control and data acquisition (SCADA)

A power generation company is modernizing a legacy SCADA environment that manages turbine controllers and safety instrumentation. The plant cannot tolerate unplanned downtime, and several programmable logic controllers (PLCs) run vendor firmware that cannot be rapidly patched or replaced. During a recent assessment, the security team discovered that an engineering workstation used to configure PLCs also had direct access to the corporate network for email and web browsing. The company wants to reduce the likelihood that malware from the enterprise network could disrupt plant operations while preserving the ability for engineers to manage controllers when needed. Which action is the MOST appropriate to implement first?

  1. A

    Place the engineering workstation and controllers on a segmented industrial network separated from the corporate network by an industrial DMZ and tightly controlled firewall rules

  2. B

    Install a standard endpoint DLP agent on each PLC to prevent unauthorized code from being copied to controllers

  3. C

    Enable automatic operating system and firmware updates on all PLCs and HMIs so vulnerabilities are remediated immediately

  4. D

    Allow engineers to continue using the same workstation for internet access, but require complex passwords and quarterly security awareness training

Show answer and explanation

Correct answer: A

Explanation

In ICS/SCADA environments, the most effective first step is often to reduce exposure through architecture and segmentation rather than relying on traditional IT controls alone. Security guidance from NIST SP 800-82, Guide to Operational Technology (OT) Security, emphasizes network segmentation between enterprise and industrial networks, use of DMZs, restricted communications paths, and careful control of engineering workstation access. Legacy PLCs and other control devices frequently cannot be patched quickly, cannot run standard endpoint agents, and may be sensitive to changes. Because the scenario highlights a shared engineering workstation with both corporate and control network access, the highest-priority risk is malware propagation from IT to OT. Establishing a separated industrial network with an industrial DMZ and tightly scoped firewall rules is the most appropriate first mitigation to reduce attack surface while maintaining operational access.

  • A. Correct.

    Correct. Segmenting the ICS/SCADA environment from the enterprise network is a primary security control for operational technology. Using an industrial DMZ and restrictive firewall rules limits direct pathways from business systems to engineering workstations and PLCs, reducing the risk that malware introduced through email or web browsing can reach critical control assets. This approach also supports operational requirements because it can preserve managed access for engineering tasks without requiring immediate patching of fragile legacy devices.

  • B. Incorrect.

    Incorrect. PLCs generally do not support standard endpoint DLP agents, and applying traditional IT endpoint controls directly to industrial controllers is often technically impossible or operationally unsafe. This option reflects a common misconception that all IT security tools can be deployed in OT environments. Security for PLCs is more commonly achieved through network isolation, allowlisting where supported, controlled engineering access, and vendor-approved hardening methods.

  • C. Incorrect.

    Incorrect. Immediate automatic updates are typically inappropriate in ICS environments because availability and safety are prioritized, and patches must usually be tested before deployment. Many PLCs and HMIs have strict vendor support requirements, maintenance windows, and compatibility concerns. Automatically pushing updates could cause outages or unsafe states. While patch management matters, it is not the best first action in this scenario.

  • D. Incorrect.

    Incorrect. Strong passwords and awareness training are useful administrative controls, but they do not adequately address the architectural risk created by a dual-homed or broadly connected engineering workstation. If the workstation continues to browse the internet and access email while connected to PLC management functions, malware exposure remains high. This option may appeal to candidates who focus on general-purpose security practices instead of the more critical OT network design issue.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam