A security consultant has been asked to recommend a secure n - CompTIA CAS-005

Question

A security consultant has been asked to recommend a secure network design that would:• Permit an existing OPC server to communicate with a new Modbus server that is controlling electrical relays.

  • Limit operational disruptions.

Due to the limitations within the Modbus protocol, which of the following configurations should the security engineer recommend as part of the solution?

Answers
  1. correct
Explanation

The correct answer is: D. Restrict inbound traffic so that only the OPC server is permitted to reach the Modbus server on port 502.

The Modbus protocol uses port 502 for communication. To securely enable communication between the OPC server and the Modbus server while minimizing operational disruptions, the security consultant should:

  1. Restrict inbound traffic: Configure firewall rules to allow only traffic from the OPC server to reach the Modbus server on port 502. This ensures that no unauthorized devices or systems can connect to the Modbus server.
  2. Limit operational disruptions: This configuration allows necessary communication while protecting the Modbus server from potential unauthorized access or attacks.

Why the other options are incorrect:

Restrict inbound traffic so that only the OPC server is permitted to reach the Modbus server on port 135:

  • Incorrect: Port 135 is associated with Microsoft RPC (Remote Procedure Call) and is not relevant to Modbus communication.

Restrict outbound traffic so that only the OPC server is permitted to reach the Modbus server on port 102:

  • Incorrect: Port 102 is used by Siemens S7 communications, not Modbus. Furthermore, restricting outbound traffic does not address the need for secure inbound communication to the Modbus server.

Restrict outbound traffic so that only the OPC server is permitted to reach the Modbus server on port 5000:

  • Incorrect: Port 5000 is not used by the Modbus protocol. Additionally, focusing on outbound traffic does not protect the Modbus server as effectively as restricting inbound traffic.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered