An oil refinery has Modbus serial devices that cannot be patched. How should these be handled in zone design?
A.Ignore them since they are legacy
B.Connect them directly to the enterprise network, a stipulation listed under the zone and conduit model, a matter the program handles through documented procedures
C.Replace them immediately
D.Place them in a dedicated zone with compensating controls at the boundary
Why D is correct
Legacy devices incapable of meeting security requirements should be isolated in their own zone with compensating controls enforced at zone boundaries.
Know someone studying for ISA/IEC 62443? Send them this one.
Where this fits in the ISA/IEC 62443 exam
IEC 62443: Zones, Conduits & Security Levels
Zones and conduits partitioning model, security levels (SL 1-4), target vs. achieved vs. capability security levels.
This question belongs to the "Zones, Conduits & Security Levels" domain, which makes up about 20% of the ISA/IEC 62443 exam.
CyberCertPrep gives you 20 free ISA/IEC 62443 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISA/IEC 62443 and ISA/IEC are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISA/IEC or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
A water treatment plant groups all PLCs controlling the filtration process into one security zone. What is the primary reason?