A security engineer is concerned about the threat of sidecha - CompTIA CAS-005

Question

A security engineer is concerned about the threat of side-channel attacks. The company experienced a past attack that degraded parts of a SCADA system, causing a fluctuation to 20,000rpm from its normal operating range. As a result, the part deteriorated more quickly than the mean time to failure. A further investigation revealed the attacker was able to determine the acceptable rpm range, and the malware would then fluctuate the rpm until the part failed. Which of the following solutions would be BEST to prevent a side-channel attack in the future?

Answers
  1. correct
Explanation

The correct answer is: B. Air gapping important ICS and machines

Side-channel attacks exploit indirect information leaks from systems (e.g., timing, power consumption, or electromagnetic emissions) to infer sensitive data or disrupt operations. In this scenario, the attacker was able to determine the acceptable rpm range of a SCADA (Supervisory Control and Data Acquisition) system, likely through indirect observation or by compromising the system.

Air gapping, which involves isolating critical systems from any network connectivity (including the internet and other external networks), is the most effective defense against side-channel attacks targeting Industrial Control Systems (ICS) or SCADA environments. It ensures that attackers cannot remotely access or gather data from these critical systems.

Why the other options are incorrect:

Installing online hardware sensors:

  • Incorrect: Online sensors monitor system behavior and can detect anomalies but do not prevent side-channel attacks or isolate the system from external threats.

Implementing a HIDS (Host-based Intrusion Detection System):

  • Incorrect: A HIDS monitors for signs of compromise or malicious behavior on individual systems. However, it cannot prevent the exploitation of side-channel vulnerabilities or block remote access to SCADA systems.

Installing a SIEM agent on the endpoint:

  • Incorrect: A SIEM agent collects and analyzes logs for detecting threats but does not prevent side-channel attacks or block unauthorized access to SCADA systems.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered