Question 1 of 15 OT Systems and Safety Foundations
In an operational technology environment, which priority typically comes first when a control decision must be made?
A Confidentiality of business email B Marketing brand image C Software licensing counts D Safety of people and physical processes
Question 2 of 15 OT Systems and Safety Foundations
What is the primary function of a safety instrumented system in an industrial plant?
A To bring the process to a safe state when dangerous conditions occur B To generate marketing reports C To manage employee payroll D To host the corporate website
Question 3 of 15 OT Systems and Safety Foundations
Which describes the purpose of network segmentation between IT and OT networks?
A To make the OT network faster for gaming B To limit how threats can move from business systems into control systems C To remove the need for any monitoring D To let all traffic flow freely for convenience
Question 4 of 15 OT Risk Management
A risk assessment for a control system should weigh the consequence of failure most heavily in terms of what?
A Physical, safety, and environmental impact B Number of social media followers C Office snack inventory D Color of the operator screens
Question 5 of 15 OT Risk Management
Why is patching often delayed on OT devices compared with IT systems?
A Because OT devices never have vulnerabilities B Because vendors forbid all updates permanently C Because uptime and validated operation are critical and patches must be tested against process safety D Because patching is illegal in OT
Question 6 of 15 OT Threat Intelligence
A plant wants to understand which adversaries might target its sector and how. What capability provides this?
A A generic office antivirus alone B Threat intelligence focused on OT and the relevant industry C A payroll audit D A social media contest
Question 7 of 15 OT Threat Intelligence
What makes OT focused threat intelligence different from typical IT threat feeds?
A It only lists office phishing subjects B It addresses control protocols, physical processes, and specialized adversary tradecraft C It ignores industrial systems entirely D It is limited to consumer devices
Question 8 of 15 OT Cybersecurity Architecture Design and Engineering
When designing a secure OT architecture, why is a demilitarized zone placed between enterprise and control networks?
A To broker and inspect the limited traffic that must cross between the two zones B To speed up video streaming C To store customer marketing lists D To eliminate the need for firewalls
Question 9 of 15 OT Cybersecurity Architecture Design and Engineering
Which principle guides granting control system access to operators and engineers?
A Everyone gets administrator rights for speed B No one is ever allowed any access C Least privilege, granting only the access required for the role D Access is decided by seniority alone
Question 10 of 15 OT Cybersecurity Architecture Design and Engineering
A defense in depth design for OT relies on what?
A A single strong password on one device B One firewall and nothing else C Multiple layered controls so one failure does not expose the whole process D Trusting that attackers will not try
Question 11 of 15 OT Security Operations
Continuous monitoring of an OT network should prioritize detection of what?
A Anomalous commands or traffic that could affect the physical process B The lunch schedule of operators C Which songs are played in the break room D The color scheme of dashboards
Question 12 of 15 OT Security Operations
Why is passive monitoring often preferred over active scanning in OT environments?
A Passive monitoring is illegal B Active scanning is always faster and harmless C Passive monitoring sees nothing at all D Active scanning can disrupt sensitive control devices, so passive observation is safer
Question 13 of 15 OT Incident Management
During an incident on a control system, what typically takes precedence over full forensic preservation?
A Preserving marketing analytics B Maintaining or safely restoring the physical process and protecting people C Updating the company blog D Rebranding the operator console
Question 14 of 15 OT Incident Management
An OT incident response plan should be exercised how?
A Only by reading it once a year B By assuming it will never be needed C Through drills and tabletop exercises involving both security and process engineers D By keeping it secret from operators
Question 15 of 15 OT Incident Management
After an OT incident is contained, why is coordination with process engineers essential during recovery?
A Because engineers handle the marketing rollout B Because they approve social media posts C Because recovery has no safety implications D Because restoring control systems incorrectly can create new safety hazards