exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 303 discussion

Actual exam question from CompTIA's CAS-004
Question #: 303
Topic #: 1
[All CAS-004 Questions]

A security engineer is concerned about the threat of side-channel attacks. The company experienced a past attack that degraded parts of a SCADA system, causing a fluctuation to 20,000rpm from its normal operating range. As a result, the part deteriorated more quickly than the mean time to failure. A further investigation revealed the attacker was able to determine the acceptable rpm range, and the malware would then fluctuate the rpm until the part failed. Which of the following solutions would be BEST to prevent a side-channel attack in the future?

  • A. Installing online hardware sensors
  • B. Air gapping important ICS and machines
  • C. Implementing a HIDS
  • D. Installing a SIEM agent on the endpoint
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
f13e9a2
1 month, 2 weeks ago
Selected Answer: B
This one is funny because the question is clearly referencing Stuxnet which famously jumped and air gap due to user behavior. The malware modified the RPM to cause the refinement of nuclear material to fail and damage the centrifuge. So, the answer is B but that did not work.
upvoted 1 times
...
ElDirec
10 months, 3 weeks ago
Selected Answer: B
The best solution to prevent a side-channel attack in the future, given the scenario, would be B. Air gapping important ICS and machines. Air gapping is a security measure that involves isolating a computer or network and preventing it from establishing an external connection. This means that an air-gapped system does not connect to the internet or to other systems that are connected to the internet. In the context of a SCADA system, this would prevent an attacker from being able to access the system remotely, thereby significantly reducing the risk of a side-channel attack.
upvoted 1 times
...
oskinoo
1 year, 1 month ago
Air gapping important ICS and machines (Option B) would be the best solution to prevent a side-channel attack in the future. Air gapping involves physically isolating a computer or network and preventing it from establishing an external connection. For example, an air-gapped computer is not connected to the internet or to any other systems that are connected to the internet. This makes it extremely difficult for an attacker to access the system and carry out attacks like the one described. While other solutions like installing online hardware sensors (Option A), implementing a Host-based Intrusion Detection System (HIDS) (Option C), and installing a Security Information and Event Management (SIEM) agent on the endpoint (Option D) can also provide certain security benefits, they do not directly address the specific threat of side-channel attacks.
upvoted 1 times
...
32d799a
1 year, 2 months ago
Selected Answer: B
Air gapping important ICS and machines. This is because removing the possibility of remote access to sensitive systems is a direct counter to the described attack.
upvoted 1 times
...
CXSSP
1 year, 3 months ago
Selected Answer: B
B appears to be the correct answer
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...