Page | 1
IEC 62443 Questions with Detailed Verified
Answers
IACS Ans: Industrial Automation and Control Systems. Example: A
nuclear power plant control room
Threat Ans: The adversary's goals or what they might try to do a
system. Example: steal money or steal passwords.
Threat Agent Ans: The attacker or adversary. Example: some bad guy
in North Korea.
Asset Ans: An abstract or concrete resource that must be protected
from misuse by an adversary. Example: Credit card number, web server
Attack pattern Ans: General strategies an adversary might use to break
into a system. Not a specific vulnerability. Example: SQL injection, or
buffer overflow
Exploit Ans: Instance of an attack pattern. Taking advantage of a
specific flaw to do something bad. Example: buffer overflow in a JSON
parsing library
Attack Ans: Act of carrying out an exploit
, Page | 2
ICS Ans: Industrial control systems
CRT testing Ans: Communication Robustness testing
Cyber Priorities of an IT department Ans: (1) Confidentiality (2)
integrity (3) availability
Cyber Priorities for ICS Ans: (1) availability (2) integrity (3)
confidentiality
ISO 27001 Ans: General IT security certification
Software security assurance Ans: Security level of software depends on
the consequences of the software being compromised. Example:
Wikipedia needs less security than a nuclear power plant
4 main themes of IEC 62443 Ans: (1) General
(2) Policies and Procedures
(3) System
(4) Component
8 fundamental practices in IEC 62443 Ans: (1) Security management
(2) Specification of security requirements
(3) Secure by design
(4) Secure implementation
(5) Security verification and validation testing
IEC 62443 Questions with Detailed Verified
Answers
IACS Ans: Industrial Automation and Control Systems. Example: A
nuclear power plant control room
Threat Ans: The adversary's goals or what they might try to do a
system. Example: steal money or steal passwords.
Threat Agent Ans: The attacker or adversary. Example: some bad guy
in North Korea.
Asset Ans: An abstract or concrete resource that must be protected
from misuse by an adversary. Example: Credit card number, web server
Attack pattern Ans: General strategies an adversary might use to break
into a system. Not a specific vulnerability. Example: SQL injection, or
buffer overflow
Exploit Ans: Instance of an attack pattern. Taking advantage of a
specific flaw to do something bad. Example: buffer overflow in a JSON
parsing library
Attack Ans: Act of carrying out an exploit
, Page | 2
ICS Ans: Industrial control systems
CRT testing Ans: Communication Robustness testing
Cyber Priorities of an IT department Ans: (1) Confidentiality (2)
integrity (3) availability
Cyber Priorities for ICS Ans: (1) availability (2) integrity (3)
confidentiality
ISO 27001 Ans: General IT security certification
Software security assurance Ans: Security level of software depends on
the consequences of the software being compromised. Example:
Wikipedia needs less security than a nuclear power plant
4 main themes of IEC 62443 Ans: (1) General
(2) Policies and Procedures
(3) System
(4) Component
8 fundamental practices in IEC 62443 Ans: (1) Security management
(2) Specification of security requirements
(3) Secure by design
(4) Secure implementation
(5) Security verification and validation testing