A pharma company has validated systems that cannot be patched. What zone strategy is appropriate?
A.Place them in the enterprise zone
B.Connect them to the Internet for updates
C.Leave them unprotected
D.Isolate them in a dedicated zone with strict conduit controls and compensating countermeasures
Why D is correct
Validated systems that cannot be patched should be isolated in dedicated zones with compensating controls such as strict firewall rules and network monitoring.
Know someone studying for ISA/IEC 62443? Send them this one.
Where this fits in the ISA/IEC 62443 exam
IEC 62443: Zones, Conduits & Security Levels
Zones and conduits partitioning model, security levels (SL 1-4), target vs. achieved vs. capability security levels.
This question belongs to the "Zones, Conduits & Security Levels" domain, which makes up about 20% of the ISA/IEC 62443 exam.
CyberCertPrep gives you 20 free ISA/IEC 62443 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISA/IEC 62443 and ISA/IEC are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISA/IEC or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
A water treatment plant groups all PLCs controlling the filtration process into one security zone. What is the primary reason?