312-50 exam dumps

312-50 practice question 421 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 421

Single answer▪ OT Concepts

During an authorized security assessment of a water treatment plant, you are asked to identify a safe initial approach for evaluating the Operational Technology (OT) environment without disrupting physical processes. The plant uses PLCs to control pumps and valves, HMIs for operator monitoring, and a historian connected through an industrial DMZ. Which action is the MOST appropriate first step for the ethical hacker?

  1. A

    Passively map network communications and asset relationships from a SPAN/TAP point before attempting any direct interaction with PLCs

  2. B

    Run a full-rate Nmap scan with service detection directly against all PLCs and HMIs during production hours to quickly inventory assets

  3. C

    Upload a benign test logic change to one PLC to confirm whether change management controls are effective

  4. D

    Force-fail a pump control process from the HMI to observe whether the safety instrumented system responds correctly

Show answer and explanation

Correct answer: A

Explanation

The best answer is to begin with passive visibility. OT environments differ from traditional IT because the consequences of testing can include equipment damage, unsafe states, environmental release, or service interruption. Ethical hackers assessing ICS/OT should prioritize non-intrusive methods first, such as reviewing architecture, identifying conduits and zones, and passively observing protocols and communications. This approach is consistent with guidance from industrial security best practices such as NIST SP 800-82, which emphasizes the unique reliability and safety requirements of Industrial Control Systems, and ISA/IEC 62443 concepts around segmentation and risk reduction. In practical terms, starting with passive collection helps identify PLCs, HMIs, historians, engineering workstations, and communication patterns without risking unintended state changes in the process.

  • A. Correct.

    Correct. In OT environments, safety and availability take priority because actions can affect real-world processes. A passive assessment from a SPAN or TAP is generally the safest initial step to understand communications, protocols, and asset relationships without introducing scan traffic or commands to fragile industrial devices. This aligns with common OT assessment best practices that recommend passive discovery first, especially in production environments.

  • B. Incorrect.

    Incorrect. Traditional high-rate active scanning and service detection can destabilize OT assets, including PLCs, RTUs, legacy HMIs, and embedded devices that are not designed to tolerate aggressive probing. Although asset inventory is important, directly scanning production control devices during operations is not an appropriate first step in most OT assessments.

  • C. Incorrect.

    Incorrect. Even a 'benign' logic change is an active modification to a control device and can create process risk, trigger alarms, alter timing, or violate safety and change-control requirements. In OT, unauthorized or unnecessary writes to PLC logic are typically avoided unless explicitly planned, approved, and tested in a maintenance window or lab environment.

  • D. Incorrect.

    Incorrect. Intentionally causing a process fault to test the safety response is highly intrusive and can create hazardous conditions. Safety instrumented systems are designed to protect people, equipment, and the environment; testing them requires formal engineering procedures, authorization, and operational coordination, not an initial penetration testing step.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam