exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 35 discussion

Actual exam question from CompTIA's CAS-004
Question #: 35
Topic #: 1
[All CAS-004 Questions]

An energy company is required to report the average pressure of natural gas used over the past quarter. A PLC sends data to a historian server that creates the required reports.
Which of the following historian server locations will allow the business to get the required reports in an ׀׀¢ and IT environment?

  • A. In the ׀׀¢ environment, use a VPN from the IT environment into the ׀׀¢ environment.
  • B. In the ׀׀¢ environment, allow IT traffic into the ׀׀¢ environment.
  • C. In the IT environment, allow PLCs to send data from the ׀׀¢ environment to the IT environment.
  • D. Use a screened subnet between the ׀׀¢ and IT environments.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BiteSize
Highly Voted 1 year, 11 months ago
Selected Answer: D
D. Screen subnet is the standard used when creating a gap between networks A & B = VPN's are secure but IT to OT environment is backwards. because you DON'T want outside access to OT env. C = is close because you need to allow the traffic, but you need to find a way to secure it via segmentation (TAXII Server, Guacamole, DMZ) Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 7 times
...
Bdav
Most Recent 4 weeks ago
Selected Answer: D
Per NIST Special Publication 800-82: Guide to Industrial Control Systems (ICS) Security. "In general, the best solution is to avoid two-one systems (no DMZ) and use a three-zone design, placing the data collector in the control network and the historian component in the DMZ."
upvoted 1 times
...
Bdav
4 weeks ago
Selected Answer: D
Per NIST Special Publication 800-82: Guide to Industrial Control Systems (ICS) Security. "In general, the best solution is to avoid two-one systems (no DMZ) and use a three-zone design, placing the data collector in the control network and the historian component in the DMZ."
upvoted 1 times
...
23169fd
11 months, 3 weeks ago
Selected Answer: D
A screened subnet, also known as a Demilitarized Zone (DMZ), acts as an intermediary network that separates the ICS and IT environments. This approach ensures that data can be securely transferred between the two environments without direct exposure. The historian server can be placed in the DMZ, allowing it to collect data from the ICS environment and generate reports accessible from the IT environment. This setup minimizes risk and maintains a robust security posture by ensuring that neither environment has direct access to the other.
upvoted 1 times
...
p1s3c
2 years, 1 month ago
Selected Answer: D
D. Use a screened subnet between the ׀׀¢ and IT environments. A screened subnet (also known as a DMZ) is a network segment that is isolated from both the internal network and the internet by firewalls. It allows for secure communication between different networks, such as the ׀׀¢ and IT environments, while providing an additional layer of protection. By placing the historian server in the screened subnet, it can receive data from the PLCs in the ׀׀¢ environment, and the IT environment can retrieve the reports without compromising security. This is the best option to allow for secure communication between the two environments.
upvoted 4 times
...
BreakOff874
2 years, 2 months ago
Selected Answer: D
D. Use a screened subnet between the OT and IT environments. A screened subnet, also known as a demilitarized zone (DMZ), provides a secure area between the OT and IT environments that can be used to allow communication between the two environments while maintaining security. By placing the historian server in the screened subnet, the energy company can allow data to be transferred between the PLCs in the OT environment and the IT environment, while also ensuring that the OT environment is isolated from the internet and other external threats.
upvoted 3 times
...
Geofab
2 years, 2 months ago
Selected Answer: D
agree with D. screened subnet seems logical and secure. a good way to separate the IT and OT networks
upvoted 3 times
...
margomi86
2 years, 3 months ago
Selected Answer: D
In order to allow the business to get the required reports in an IT and OT environment, it would be best to use a screened subnet between the OT and IT environments. This would allow for controlled access between the two environments and protect against unauthorized access or attacks. Option D is the correct answer. Option A and B can introduce security risks to both environments and Option C would not be the best approach for maintaining a secure and separate IT and OT environment.
upvoted 3 times
...
milkyzzz
2 years, 5 months ago
why not D?
upvoted 4 times
...
RevZig67
3 years, 2 months ago
Answer C . You would want communication to start in OT environment and send it up through levels to IT.
upvoted 2 times
...
dgfhyjfghfgfkfhd
3 years, 2 months ago
Selected Answer: C
A seems incorrect. It's worded to sound like there's a VPN server somewhere in the OT environment, which is backwards. The PLC data would be getting forwarded to the IT environment, not vice versa.
upvoted 3 times
dgfhyjfghfgfkfhd
3 years, 2 months ago
...and you wouldn't host a VPN server outside the IT environment.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...