Page | 1
IEC 62443-IC33 Risk Assessment Specialist
Questions with Detailed Verified Answers
What type of vulnerability assessment technique involves using exploit
tools? Ans: Penetration Testing (Most Invasive)
Which vulnerability assessment provides feedback on performance in
comparison to industry peers? Ans: Gap Assessment (High Level - Least
invasive)
Which type of assessment may include reviewing document, system
walk-thru, traffic analysis, or ARP tables? Ans: Passive Assessment
Vulnerability Assessment Ans: Defines,
Identifies,
Classifies the security vulnerabilities
Penetration Testing Ans: Exploits vulnerabilities
Which type of assessment uses tools to discover devices and
vulnerabilities of the IACS? Ans: Active Assessment
, Page | 2
What type of vulnerability assessment identifies the worst-case
unmitigated risk that the SuC presents to the organization? Ans: Cyber
Risk Assessment
Which gap assessment tool was created by the US DHS? Ans: CSET
What type of tool is used to capture and display Ethernet
communications? Ans: Packet Capture
A feature that sends a copy of a network from one or more switch ports
to a special monitoring port is called: Ans: Port Mirroring
Which computer programs assess computers, computer systems,
networks or applications for weaknesses against databases of know
vulnerabilities? Ans: Network Vulnerability Scanning Tools
Nessuss, Nexpose, and Retina are assessment tools used to discover:
Ans: System Vulnerabilities
What is the entity that can manifest a threat? Ans: Threat source
What is the term for the likelihood of the threat scenario occurring and
leading to the final consequence taking into account all protection
measures and cybersecurity countermeasures in place? Ans: Mitigated
Threat Likelihood (MTL)
Delaying or blocking the flow of information in a system is an example of
the following threat vector: Ans: Denial of Service
Which threat vector involves the unauthorized redirection of data? Ans:
Information Disclosure
IEC 62443-IC33 Risk Assessment Specialist
Questions with Detailed Verified Answers
What type of vulnerability assessment technique involves using exploit
tools? Ans: Penetration Testing (Most Invasive)
Which vulnerability assessment provides feedback on performance in
comparison to industry peers? Ans: Gap Assessment (High Level - Least
invasive)
Which type of assessment may include reviewing document, system
walk-thru, traffic analysis, or ARP tables? Ans: Passive Assessment
Vulnerability Assessment Ans: Defines,
Identifies,
Classifies the security vulnerabilities
Penetration Testing Ans: Exploits vulnerabilities
Which type of assessment uses tools to discover devices and
vulnerabilities of the IACS? Ans: Active Assessment
, Page | 2
What type of vulnerability assessment identifies the worst-case
unmitigated risk that the SuC presents to the organization? Ans: Cyber
Risk Assessment
Which gap assessment tool was created by the US DHS? Ans: CSET
What type of tool is used to capture and display Ethernet
communications? Ans: Packet Capture
A feature that sends a copy of a network from one or more switch ports
to a special monitoring port is called: Ans: Port Mirroring
Which computer programs assess computers, computer systems,
networks or applications for weaknesses against databases of know
vulnerabilities? Ans: Network Vulnerability Scanning Tools
Nessuss, Nexpose, and Retina are assessment tools used to discover:
Ans: System Vulnerabilities
What is the entity that can manifest a threat? Ans: Threat source
What is the term for the likelihood of the threat scenario occurring and
leading to the final consequence taking into account all protection
measures and cybersecurity countermeasures in place? Ans: Mitigated
Threat Likelihood (MTL)
Delaying or blocking the flow of information in a system is an example of
the following threat vector: Ans: Denial of Service
Which threat vector involves the unauthorized redirection of data? Ans:
Information Disclosure