312-50 exam dumps

312-50 practice question 429 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 429

Select 3▪ OT Attack Countermeasures

A manufacturing company discovers that an engineering workstation in its OT environment was infected with malware after a contractor used a USB drive to transfer PLC logic updates. The plant cannot tolerate unplanned downtime, and the security team has been asked to recommend countermeasures that reduce the risk of similar attacks without disrupting control processes. Which THREE actions are the most appropriate OT attack countermeasures in this scenario?

  1. A

    Implement a removable-media control process with malware scanning at a staging station before any USB device is connected to engineering workstations

  2. B

    Place a firewall/industrial DMZ between the IT and OT networks and restrict communications to explicitly approved protocols and hosts

  3. C

    Deploy aggressive, enterprise-style vulnerability scans directly against PLCs and HMIs during production hours to find latent malware

  4. D

    Use application whitelisting on engineering workstations so only approved software and tools can execute

  5. E

    Allow contractors to connect personal laptops directly to the control network if they use strong passwords

Show answer and explanation

Correct answers: A, B, D

Explanation

The best answer set is 1, 2, and 4 because the scenario focuses on preventing malware introduction through USB and limiting future OT compromise without causing unplanned downtime. In OT environments, countermeasures should emphasize safety, availability, and controlled change. Removable-media governance directly addresses the initial infection vector. Network segmentation using an industrial DMZ and restrictive firewall rules limits propagation between enterprise and control networks. Application whitelisting on engineering workstations helps stop unauthorized code execution on high-value OT endpoints.

By contrast, aggressive active scanning during production is generally discouraged in OT because many industrial devices are sensitive to unexpected traffic or resource spikes. Likewise, permitting direct contractor laptop access is inconsistent with OT security principles because unmanaged devices significantly increase the attack surface.

These recommendations are consistent with established OT/ICS guidance such as the Purdue-style segmentation approach, NIST SP 800-82 guidance for Industrial Control Systems security, and ISA/IEC 62443 principles emphasizing zones, conduits, least functionality, and controlled access. In practice, CEH candidates should recognize that effective OT attack countermeasures differ from standard IT responses: they must reduce cyber risk while preserving process safety and operational continuity.

  • A. Correct.

    Correct. Removable media is a well-known infection vector in OT environments, especially where systems are isolated or updates are transferred manually. Using a dedicated staging/scanning station and enforcing removable-media controls reduces the chance that malware reaches engineering workstations or control assets. This is a practical control because it addresses the exact attack path in the scenario without requiring disruptive changes to the process network.

  • B. Correct.

    Correct. Segmenting IT and OT with an industrial firewall or industrial DMZ is a core OT defensive measure. Allow-listing only required communications between zones reduces lateral movement and limits the impact of malware originating from business systems or external connections. This aligns with common OT architecture guidance and is less disruptive than broad changes to control logic or production operations.

  • C. Incorrect.

    Incorrect. Direct, aggressive vulnerability scanning of PLCs, HMIs, and other OT assets during production can destabilize fragile devices, consume limited resources, or interrupt control traffic. In OT, security testing must be carefully coordinated, often using passive monitoring or vendor-approved methods during maintenance windows. Choosing this option reflects the common but dangerous misconception that IT-style scanning can be safely applied to control systems at any time.

  • D. Correct.

    Correct. Application whitelisting is widely recommended for fixed-function OT systems such as engineering workstations and HMIs. Because these systems typically run a limited, known set of applications, allow-listing can effectively block unauthorized executables, scripts, and malware introduced through USB or other means. It is a strong preventive control that fits OT's stability requirements better than frequent software changes.

  • E. Incorrect.

    Incorrect. Strong passwords alone do not make unmanaged contractor laptops safe for direct connection to control networks. Personal devices may be unpatched, infected, or improperly configured, creating a significant risk to OT assets. Best practice is to control third-party access through managed jump hosts, segmented remote access, approval workflows, and monitoring rather than allowing direct unmanaged connections.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam