IEC 62443-IC33 RISK ASSESSMENT
SPECIALIST QUESTIONS AND
ANSWERS
Whatttypetoftvulnerabilitytassessmentttechniquetinvolvestusingtexploitttools?t-tans-
PenetrationtTestingt(MosttInvasive)
Whichtvulnerabilitytassessmenttprovidestfeedbacktontperformancetintcomparisonttoti
ndustrytpeers?t-tans-GaptAssessmentt(HightLevelt-tLeasttinvasive)
Whichttypetoftassessmenttmaytincludetreviewingtdocument,tsystemtwalk-
thru,ttraffictanalysis,tortARPttables?t-tans-PassivetAssessment
VulnerabilitytAssessmentt-tans-Defines,
Identifies,
Classifiestthetsecuritytvulnerabilities
PenetrationtTestingt-tans-Exploitstvulnerabilities
WhichttypetoftassessmenttusesttoolsttotdiscovertdevicestandtvulnerabilitiestoftthetI
ACS?t-tans-ActivetAssessment
Whatttypetoftvulnerabilitytassessmenttidentifiestthetworst-
casetunmitigatedtrisktthattthetSuCtpresentsttotthetorganization?t-tans-
CybertRisktAssessment
WhichtgaptassessmentttooltwastcreatedtbytthetUStDHS?t-tans-CSET
WhatttypetofttooltistusedttotcapturetandtdisplaytEthernettcommunications?t-tans-
PackettCapture
Atfeaturetthattsendstatcopytoftatnetworktfromtonetortmoretswitchtportsttotatspecial
tmonitoringtporttistcalled:t-tans-PorttMirroring
Whichtcomputertprogramstassesstcomputers,tcomputertsystems,tnetworkstortapplica
tionstfortweaknessestagainsttdatabasestoftknowtvulnerabilities?t-tans-
NetworktVulnerabilitytScanningtTools
Nessuss,tNexpose,tandtRetinataretassessmentttoolstusedttotdiscover:t-tans-
SystemtVulnerabilities
, Whattistthetentitytthattcantmanifesttatthreat?t-tans-Threattsource
Whattistthettermtfortthetlikelihoodtoftthetthreattscenariotoccurringtandtleadingttotthe
tfinaltconsequencettakingtintotaccounttalltprotectiontmeasurestandtcybersecuritytcou
ntermeasurestintplace?t-tans-MitigatedtThreattLikelihoodt(MTL)
Delayingtortblockingtthetflowtoftinformationtintatsystemtistantexampletoftthetfollowin
gtthreattvector:t-tans-DenialtoftService
Whichtthreattvectortinvolvestthetunauthorizedtredirectiontoftdata?t-tans-
InformationtDisclosure
Whattistthetlikelihoodtoftthetthreattoccurringtandtleadingttotthetfinaltconsequencetwi
thouttanytcybersecuritytcountermeasurestintplace?t-tans-
UnmitigatedtThreattLikelihoodt(UTL)
CIAt-tans-Confidentiality,tIntegrity,tAvailability
Whichtoftthetfollowingtistthettermtfortthetundesirabletresulttoftantincident?t-tans-
Consequence
Whichttermtistusedttotdescribetthetpassivetcollectiontoftdatatintpackettcapturetprogr
ams?t-tans-SniffingtthetEthernet
Whattistatmeasuretoftthetdegreetoftrisktreductiontrequiredttotachievettolerabletrisk?
t-tans-CybertRisktReductiontFactor
Whattistthetformulatusedttotcalculatetrisk?t-tans-
Riskt=tThreattXtVulnerabilitytXtConsequence
WhattistatCRS?t-tans-CybersecuritytRequirementstSpecification
Whattaretthet3tphasestoftthetsecuritytlifetcycletintthet62443tStandard?t-tans-
1.tAssess
2.tDeveloptandtImplement
3.tMaintain
Continuoustprocesstneededttotminimizetrisks
WhattmakestuptthetAssesstPhase?t-tans-1.tHigh-LeveltCybertRisktAssessment
2.tAllocationtoftIACStAssetsttotSecuritytZonestandtConduits
3.tDetailedtCybertRisktAssessment
WhattaretthetkeytcomponentstoftScope?t-tans-1.tSystemtArchitecturetDiagrams
2.tDetailedtNetworktDiagrams
3.tAssettInventory
SPECIALIST QUESTIONS AND
ANSWERS
Whatttypetoftvulnerabilitytassessmentttechniquetinvolvestusingtexploitttools?t-tans-
PenetrationtTestingt(MosttInvasive)
Whichtvulnerabilitytassessmenttprovidestfeedbacktontperformancetintcomparisonttoti
ndustrytpeers?t-tans-GaptAssessmentt(HightLevelt-tLeasttinvasive)
Whichttypetoftassessmenttmaytincludetreviewingtdocument,tsystemtwalk-
thru,ttraffictanalysis,tortARPttables?t-tans-PassivetAssessment
VulnerabilitytAssessmentt-tans-Defines,
Identifies,
Classifiestthetsecuritytvulnerabilities
PenetrationtTestingt-tans-Exploitstvulnerabilities
WhichttypetoftassessmenttusesttoolsttotdiscovertdevicestandtvulnerabilitiestoftthetI
ACS?t-tans-ActivetAssessment
Whatttypetoftvulnerabilitytassessmenttidentifiestthetworst-
casetunmitigatedtrisktthattthetSuCtpresentsttotthetorganization?t-tans-
CybertRisktAssessment
WhichtgaptassessmentttooltwastcreatedtbytthetUStDHS?t-tans-CSET
WhatttypetofttooltistusedttotcapturetandtdisplaytEthernettcommunications?t-tans-
PackettCapture
Atfeaturetthattsendstatcopytoftatnetworktfromtonetortmoretswitchtportsttotatspecial
tmonitoringtporttistcalled:t-tans-PorttMirroring
Whichtcomputertprogramstassesstcomputers,tcomputertsystems,tnetworkstortapplica
tionstfortweaknessestagainsttdatabasestoftknowtvulnerabilities?t-tans-
NetworktVulnerabilitytScanningtTools
Nessuss,tNexpose,tandtRetinataretassessmentttoolstusedttotdiscover:t-tans-
SystemtVulnerabilities
, Whattistthetentitytthattcantmanifesttatthreat?t-tans-Threattsource
Whattistthettermtfortthetlikelihoodtoftthetthreattscenariotoccurringtandtleadingttotthe
tfinaltconsequencettakingtintotaccounttalltprotectiontmeasurestandtcybersecuritytcou
ntermeasurestintplace?t-tans-MitigatedtThreattLikelihoodt(MTL)
Delayingtortblockingtthetflowtoftinformationtintatsystemtistantexampletoftthetfollowin
gtthreattvector:t-tans-DenialtoftService
Whichtthreattvectortinvolvestthetunauthorizedtredirectiontoftdata?t-tans-
InformationtDisclosure
Whattistthetlikelihoodtoftthetthreattoccurringtandtleadingttotthetfinaltconsequencetwi
thouttanytcybersecuritytcountermeasurestintplace?t-tans-
UnmitigatedtThreattLikelihoodt(UTL)
CIAt-tans-Confidentiality,tIntegrity,tAvailability
Whichtoftthetfollowingtistthettermtfortthetundesirabletresulttoftantincident?t-tans-
Consequence
Whichttermtistusedttotdescribetthetpassivetcollectiontoftdatatintpackettcapturetprogr
ams?t-tans-SniffingtthetEthernet
Whattistatmeasuretoftthetdegreetoftrisktreductiontrequiredttotachievettolerabletrisk?
t-tans-CybertRisktReductiontFactor
Whattistthetformulatusedttotcalculatetrisk?t-tans-
Riskt=tThreattXtVulnerabilitytXtConsequence
WhattistatCRS?t-tans-CybersecuritytRequirementstSpecification
Whattaretthet3tphasestoftthetsecuritytlifetcycletintthet62443tStandard?t-tans-
1.tAssess
2.tDeveloptandtImplement
3.tMaintain
Continuoustprocesstneededttotminimizetrisks
WhattmakestuptthetAssesstPhase?t-tans-1.tHigh-LeveltCybertRisktAssessment
2.tAllocationtoftIACStAssetsttotSecuritytZonestandtConduits
3.tDetailedtCybertRisktAssessment
WhattaretthetkeytcomponentstoftScope?t-tans-1.tSystemtArchitecturetDiagrams
2.tDetailedtNetworktDiagrams
3.tAssettInventory