• Shuffle
    Toggle On
    Toggle Off
  • Alphabetize
    Toggle On
    Toggle Off
  • Front First
    Toggle On
    Toggle Off
  • Both Sides
    Toggle On
    Toggle Off
  • Read
    Toggle On
    Toggle Off
Reading...
Front

Card Range To Study

through

image

Play button

image

Play button

image

Progress

1/45

Click to flip

Use LEFT and RIGHT arrow keys to navigate between flashcards;

Use UP and DOWN arrow keys to flip the card;

H to show hint;

A reads text to speech;

45 Cards in this Set

  • Front
  • Back

​A term that sometimes refers to wired communication, but generally refers to wireless communication that transmits data regarding specific measurements and conditions, such as weather data transmitted from a weather balloon to ground antennas.

telemetry

​An ICS server that collects and stores raw data. This server connects to field devices from which it receives the raw data and passes that information on to other servers in the SCADA system.

​acquisitions server

​A method of authentication in which a device scans an individual's unique physical characteristics, such as the color patterns in her iris or the geometry of her hand, to verify the user's identity.

​biorecognition access

​An electronic access badge.

smart card​

​A supervisory computer or server in an ICS or SCADA system that controls the physical system. Also called the control server or the SCADA server.

​master terminal unit (MTU)

​A smart card that does not require direct contact with a proximity reader in order to be detected and read.

​prox card

​An enclosure made of conductive material that is designed to block electromagnetic signals, including Wi-Fi.

Faraday cage​

​A magnetic hard drive eraser.

​degausser

A document that details the work that must be completed for a particular project, including specifics such as tasks, deliverables, standards, payment schedule, and work timeline.​

​SOW (statement of work)

​A computer, including hardware and software, that technicians use to monitor and manage physical systems in an industrial system.

​human-machine interfaces (HMI)

​An active card, which contains an internal battery, can provide a usable range of up to what distance?

​150 m

A rollback is also known by what two terms below?​

​backleveling, ​downgrading

A server that collects and stores raw data, and connects to field devices from which it receives raw data and passes data on to other SCADA systems, is known as what two terms below?​

​acquisitions server, ​I/O server

At what type of recovery site would computers, devices, and connectivity necessary to rebuilt a network exist, and all are appropriately configured, updated, and connected to match your network's current state?​

hot site

eDiscovery and computer forensics reveal what two different types of data?​

​active data, ​ambient data

If a destructive program is running that might be destroying evidence, what should be done?​

​Pull the power cable

​In computer forensics, hidden data such as deleted files and file fragments are known as what term?

​ambient data

In order to provide access to a historian by personnel working on the corporate network that are not authorized to work on the ICS network, where should the historian be placed?​

​DMZ

The time period in which a change can be implemented is known as what option below?​

​maintenance window

Upon receipt of what type of notification is a company required to activate a defensible policy for the preservation of relevant data?​

​legal hold

What is a historian?​

​A centralized database of collected and analyzed data and control activities.

What should be the first step of a response policy?​

​Determine if escalation is necessary

What team member role coordinates the resources necessary to solve a problem?​

​manager

What team member role focuses on only one thing: solving the problem as quickly as possible?​

​technical support specialist

What team member role, if necessary, learns about the situation and the response and then acts as official spokesperson for the organization to the public or other interested parties?​

​public relations specialist

What two methods might be used by an ICS to control a physical system?​

​open loop system, ​closed loop system

​What two terms describe the process that can reveal a great deal of information, called ESI (electronically stored information)?

​eDiscovery, ​electronic discovery

What type of device can be used to erase contents of a hard drive using a magnetic field?​

​degausser

What type of physical security solution involves a device that scans an individual's unique physical characteristics?​

​biorecognition access

What type of software is a correction, improvement, or enhancement to a piece of software?​

​patch

When performing inventory on software packages, which of the following is not something that should be inventoried?​

​proprietary source code

Which of the following is NOT a step that should be taken as part of a ​response policy?

​Attempt to access files to determine if they are compromised

Which team role is the person on call who first notices or is alerted to a problem?​

​dispatcher

Which type of disaster recovery site is a place where the computers, devices, and connectivity necessary to rebuild a network exist, but they are not appropriately configured, updated, or connected?

​cold site

Which type of recovery site is a place where computers, devices, and connectivity necessary to rebuild a network exist, with some pieces ​appropriately configured, updated, or connected?

​warm site

Any device in an ICS that is motorized and can control the physical system is called a fieldbus.

False

Cipher locks are not designed for physical security, such as on an outside door.

True

Every security policy should include a response policy, which specifically defines the characteristics of an event that qualifies as a formal incident and the steps that should be followed as a result.

True

The first step in asset management is to inventory all the components on the network.​

True

The first step of a response policy should be to secure the area.​

False

A _________ is an enclosure made of a conductive material that is designed to block electromagnetic signals, including Wi-Fi.​

Faraday cage

A ____________ is a small network that is segmented from the rest of the network, and contains computers, called test beds.​

testing lab

________________is a process of investigating deeper data on a computer and will essentially autopsy the computer to discover hidden data, such as deleted files and file fragments, and who has accessed that data and when.

Computer forensics

Microsoft sometimes releases a major group of patches to Windows or a Microsoft application, which it calls a________________

Service Pack

The goal of a disaster recovery plan is to ensure___________

business continuity