NEW
Font size
WorksheetsCybersecurity and Vulnerability Quiz
Total questions: 15
Worksheet time: 8mins
A water treatment facility recently discovered that an attacker gained remote access to a pump control module. The system affected is a Programmable Logic Controller (PLC). Which type of environment has been compromised?
Traditional IT environment
Operational Technology (OT) system
Cloud-managed ICS environment
Data analytics cluster
A hospital is conducting vulnerability scanning on its patient monitoring ICS network. Analysts must avoid interrupting real-time vital-sign equipment. Which type of scanning or operational consideration is MOST critical?
Run automated exploitation scripts
Schedule scans during peak patient hours
Use nonintrusive and low-impact scanning methods
Block all outbound traffic during scans
A vulnerability report lists: Attack Vector: Network (N) Privileges Required: None (N) User Interaction: None (N) Confidentiality Impact: High (H) Given these metrics, which statement is MOST accurate regarding the vulnerability?
It is low risk because it requires physical access
It can be remotely exploited without user interaction
It cannot be exploited unless the attacker has admin privileges
It will always receive an informational score
A regional power grid operator discovers that a SCADA field device is sending inconsistent readings. An analyst suspects tampering. Which statement BEST explains why this situation is critical?
SCADA systems only store logs and are disconnected from operations
SCADA failures can disrupt command and control over critical infrastructure
SCADA devices cannot be remotely accessed
SCADA systems are part of cloud infrastructure
An analyst needs a standardized way to identify misconfigurations and software flaws across multiple vulnerability scanners. Which framework should they rely on?
ISO 27001
SCAP
OWASP
COBIT
An organization is reviewing vulnerabilities in its ICS network. One vulnerability is scored as a 9.8 Critical, but exploitation would require physically accessing a high-security area. What CVSS limitation does this highlight?
Scores cannot exceed 8.0 in OT systems
Temporal metrics overwrite base metrics
CVSS scoring may not reflect practical exploitability
Critical scores always require remote vectors
During a risk review, analysts observe that multiple infrastructure sectors—transportation, power, and communications—could all be affected by a single OT system outage. What concept does this BEST illustrate?
Patch dependency
Infrastructure interdependency
Defense-in-depth strategy
SCADA segmentation
An analyst is reviewing a CVE entry in the National Vulnerability Database. The entry displays both a Base Score and a CVSS Vector String. What is the MAIN purpose of reviewing the vector string?
It lists available patches
It identifies the vulnerability’s exploit kit
It breaks down how the score was calculated
It determines which vendor created the software
A manufacturer discovers a vulnerability that has a Medium base score but becomes High when evaluated for its specific environment. What CVSS metric category explains this change?
Base
Temporal
Environmental
Exploit code maturity
An ICS security analyst is tasked with prioritizing vulnerabilities for remediation. Which factor should be considered to ensure the most critical OT risks are addressed first?
Frequency of vulnerability scanner updates
Number of affected IT users
Vendor patch release date
CVSS Environmental score relevance
During a security assessment, an analyst notes that a vulnerability in a PLC can be exploited remotely with no authentication. Which CVSS metric would MOST influence the severity score in this scenario?
Attack Vector
Exploit Code Maturity
Report Confidence
Remediation Level
An ICS operator notices that a PLC is responding to commands with unexpected delays. What is the MOST likely security concern in this scenario?
PLC delays are always caused by hardware failure
Delayed responses may indicate unauthorized access or manipulation
PLC devices are immune to network-based attacks
ICS networks do not require monitoring for anomalies
A utility company wants to ensure its ICS vulnerability scans do not disrupt critical operations. Which scanning approach should be prioritized?
Use aggressive scanning techniques for faster results
Perform scans during system maintenance windows
Disable all network traffic before scanning
Run scans without considering device sensitivity
Jasmine is responsible for planning vulnerability scans in an ICS environment at her facility. To minimize operational risk, which of the following actions is MOST important for her to consider?
Ignore device manufacturer recommendations
Coordinate scans with system operators and maintenance schedules
Conduct scans during periods of peak activity
Use only default scanning profiles
James is responsible for managing the security of an industrial control system (ICS) at a manufacturing plant. He learns about a vulnerability that requires no user interaction, no privileges, and can be exploited over the network. What does this imply about the potential impact?
It is a low-severity issue
Only administrators are at risk
Physical access is required for exploitation
The vulnerability is likely to be easily exploited remotely
