CompTIA CASP+ (CAS-004) — Question 98

An attacker infiltrated an electricity-generation site and disabled the safety instrumented system. Ransomware was also deployed on the engineering workstation.
The environment has back-to-back firewalls separating the corporate and OT systems. Which of the following is the MOST likely security consequence of this attack?

Answer options

Correct answer: A

Explanation

The correct answer is A, as disabling the safety instrumented system can lead to unsafe operational conditions, such as a turbine overheating, which poses a physical risk. Options B and C do not represent direct consequences of the attack's nature, and D is unlikely since the data diodes are designed to prevent data exfiltration.