What remediation strategies are the most effective in reduci - CompTIA-N10-009

Question

What remediation strategies are the MOST effective in reducing the risk to an embedded ICS (Internet Connection Sharing) from a network-based compromise? (Select TWO)

Answers
  1. correct
  2. correct
Explanation

Correct Answers: B. Segmentation and D. Disabling unused services

  1. Segmentation:
    Segmentation isolates the Industrial Control Systems (ICS) from other parts of the network, reducing its exposure to potential attackers. By placing the ICS on its own subnet or VLAN and implementing strict access controls, the risk of network-based compromise is significantly reduced.

  2. Disabling unused services:
    Disabling unnecessary services and features on the ICS minimizes the attack surface. Many ICS systems have legacy or unused functionalities that can be exploited if left active. By disabling these, the system becomes less vulnerable to external threats.

Why the other options are less effective:

  • Patching:
    While patching is important, many embedded ICS systems rely on outdated or proprietary software, where patches may not be available or may disrupt operations. Therefore, it is not always a feasible primary strategy.

  • NIDS (Network-based Intrusion Detection System):
    While an NIDS can detect potential threats, it is a reactive measure that alerts to ongoing attacks. It does not prevent network-based compromises outright, unlike segmentation or reducing the system’s attack surface.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered