312-50 exam dumps

312-50 practice question 431 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 431

Select 2▪ OT Attack Countermeasures

A manufacturing company discovers that an engineering workstation in its OT environment was compromised through a phishing email. The workstation has direct access to PLCs that control a packaging line. Management wants immediate countermeasures that reduce the chance of the attacker pivoting deeper into the control network while minimizing disruption to the production process. Which TWO actions should the security team prioritize?

  1. A

    Implement network segmentation with industrial firewalls or ACLs to strictly limit communications between the engineering workstation, PLCs, and other OT assets to only required protocols and hosts

  2. B

    Run a full enterprise vulnerability scan with aggressive settings across all PLCs and HMIs during production hours to quickly identify additional weaknesses

  3. C

    Enforce application whitelisting and tightly control removable media and software execution on engineering workstations used to manage PLCs

  4. D

    Enable universal internet access from OT engineering workstations so vendors can remotely troubleshoot systems faster if another compromise occurs

  5. E

    Immediately push standard IT endpoint security agents and automated patching to all legacy OT devices regardless of vendor support status

Show answer and explanation

Correct answers: A, C

Explanation

The best immediate OT attack countermeasures in this scenario are to contain lateral movement through network segmentation and to harden the engineering workstation through application whitelisting and execution control. These measures are practical because they reduce attacker options without requiring risky changes to live PLCs. In operational technology, availability and safety are critical, so defensive actions must be effective yet minimally disruptive. Guidance from NIST SP 800-82, CISA ICS recommendations, and the ISA/IEC 62443 series consistently emphasizes segmentation, least functionality, restricted remote access, removable media control, and carefully managed change processes. By contrast, aggressive active scanning, broad internet exposure, and blindly deploying standard IT security tooling to legacy OT assets can introduce operational risk and are not appropriate first-line countermeasures in a live industrial environment.

  • A. Correct.

    Correct. In OT environments, segmentation is one of the most effective countermeasures for limiting lateral movement after a workstation compromise. Restricting traffic so engineering stations can communicate only with authorized PLCs over required industrial protocols reduces the blast radius without necessarily shutting down production. This aligns with common OT guidance such as Purdue-style zoning/conduits and ICS network segmentation practices recommended by CISA and NIST.

  • B. Incorrect.

    Incorrect. Although vulnerability identification is important, aggressive scanning of PLCs and HMIs in production OT environments can cause instability, communication interruptions, or device crashes. OT countermeasures emphasize passive monitoring, vendor-approved assessment methods, and carefully scheduled testing rather than IT-style aggressive scans during active operations.

  • C. Correct.

    Correct. Engineering workstations are high-value OT assets because they can program or reconfigure PLCs. Application whitelisting, restricting script/tool execution, and controlling removable media are well-established OT countermeasures that reduce malware execution and unauthorized changes. These controls are especially valuable when patching is limited or delayed due to operational constraints.

  • D. Incorrect.

    Incorrect. Broad internet access from OT engineering workstations increases exposure and creates additional attack paths. Secure remote access in OT should be tightly controlled, brokered, monitored, and limited to specific use cases, not opened generally for convenience. This option reflects a common but dangerous misconception that easier remote connectivity improves resilience.

  • E. Incorrect.

    Incorrect. OT systems often include fragile or vendor-specific devices that may not support standard IT agents or automated patching. Forcing unsupported controls can disrupt operations or void vendor support. In OT, compensating controls such as segmentation, allowlisting, jump hosts, and maintenance-window patching are typically preferred unless vendor validation exists.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam