CompTIA CASP+ (CAS-004) — Question 331

A security engineer is re-architecting a network environment that provides regional electric distribution services. During a pretransition baseline assessment, the engineer identified the following security-relevant characteristics of the environment:

• Enterprise IT servers and supervisory industrial systems share the same subnet.
• Supervisory controllers use the 750MHz band to direct a portion of fielded PLCs.
• Command and telemetry messages from industrial control systems are unencrypted and unauthenticated.

Which of the following re-architecture approaches would be best to reduce the company's risk?

Answer options

Correct answer: C

Explanation

Option C is correct because creating a separate network segment for enterprise IT servers and enforcing a segmentation policy with NGFW enhances security and reduces risks. The use of a WIDS also enables monitoring for unauthorized access. Options A and B do not adequately address the need for segmentation, while option D may overly restrict network functionality and does not address the lack of encryption and authentication.