2
IEC 62443 exam with precise detailed
answers
IACS - Correct answer ✔Industrial Automation and Control Systems. Example: A nuclear
power plant control room
Threat - Correct answer ✔The adversary's goals or what they might try to do a system.
Example: steal money or steal passwords.
Threat Agent - Correct answer ✔The attacker or adversary. Example: some bad guy in North
Korea.
Asset - Correct answer ✔An abstract or concrete resource that must be protected from misuse
by an adversary. Example: Credit card number, web server
Attack pattern - Correct answer ✔General strategies an adversary might use to break into a
system. Not a specific vulnerability. Example: SQL injection, or buffer overflow
Exploit - Correct answer ✔Instance of an attack pattern. Taking advantage of a specific flaw to
do something bad. Example: buffer overflow in a JSON parsing library
Attack - Correct answer ✔Act of carrying out an exploit
ICS - Correct answer ✔Industrial control systems
CRT testing - Correct answer ✔Communication Robustness testing
, 2
Cyber Priorities of an IT department - Correct answer ✔(1) Confidentiality (2) integrity (3)
availability
Cyber Priorities for ICS - Correct answer ✔(1) availability (2) integrity (3) confidentiality
ISO 27001 - Correct answer ✔General IT security certification
Software security assurance - Correct answer ✔Security level of software depends on the
consequences of the software being compromised. Example: Wikipedia needs less security
than a nuclear power plant
4 main themes of IEC 62443 - Correct answer ✔(1) General
(2) Policies and Procedures
(3) System
(4) Component
8 fundamental practices in IEC 62443 - Correct answer ✔(1) Security management
(2) Specification of security requirements
(3) Secure by design
(4) Secure implementation
(5) Security verification and validation testing
(6) Management of security related issues
(7) Security update management
(8) Security guidelines
IEC 62443 exam with precise detailed
answers
IACS - Correct answer ✔Industrial Automation and Control Systems. Example: A nuclear
power plant control room
Threat - Correct answer ✔The adversary's goals or what they might try to do a system.
Example: steal money or steal passwords.
Threat Agent - Correct answer ✔The attacker or adversary. Example: some bad guy in North
Korea.
Asset - Correct answer ✔An abstract or concrete resource that must be protected from misuse
by an adversary. Example: Credit card number, web server
Attack pattern - Correct answer ✔General strategies an adversary might use to break into a
system. Not a specific vulnerability. Example: SQL injection, or buffer overflow
Exploit - Correct answer ✔Instance of an attack pattern. Taking advantage of a specific flaw to
do something bad. Example: buffer overflow in a JSON parsing library
Attack - Correct answer ✔Act of carrying out an exploit
ICS - Correct answer ✔Industrial control systems
CRT testing - Correct answer ✔Communication Robustness testing
, 2
Cyber Priorities of an IT department - Correct answer ✔(1) Confidentiality (2) integrity (3)
availability
Cyber Priorities for ICS - Correct answer ✔(1) availability (2) integrity (3) confidentiality
ISO 27001 - Correct answer ✔General IT security certification
Software security assurance - Correct answer ✔Security level of software depends on the
consequences of the software being compromised. Example: Wikipedia needs less security
than a nuclear power plant
4 main themes of IEC 62443 - Correct answer ✔(1) General
(2) Policies and Procedures
(3) System
(4) Component
8 fundamental practices in IEC 62443 - Correct answer ✔(1) Security management
(2) Specification of security requirements
(3) Secure by design
(4) Secure implementation
(5) Security verification and validation testing
(6) Management of security related issues
(7) Security update management
(8) Security guidelines