Certified Information Systems Security Professional (CISSP) — Question 392
What is the PRIMARY consideration when testing industrial control systems (ICS) for security weaknesses?
Answer options
- A. ICS often run on UNIX operating systems.
- B. ICS often do not have availability requirements.
- C. ICS are often sensitive to unexpected traffic.
- D. ICS are often isolated and difficult to access.
Correct answer: C
Explanation
The correct answer is C because industrial control systems are designed to operate in specific environments and can be disrupted by unexpected network traffic, which may lead to operational failures. Options A and B are incorrect as they do not reflect the primary concern of security testing, while option D, while relevant, does not directly address the impact of unexpected traffic on the system's functionality.