Which IDS rule most directly exposes an unauthorized program download to a Siemens S7 controller?
- A.Alert on S7comm download or stop commands from non-engineering hosts
- B.Alert on SNMP traps that carry link-up events from switches
- C.Alert on S7comm read requests issued by the registered operator HMI node
- D.Alert on DNS lookups for the vendor update portal from the DMZ
Why A is correct
Download and stop functions are the S7comm operations that change controller logic or state, so limiting them to approved engineering stations catches misuse. HMI reads and DNS or SNMP noise are normal.
Know someone studying for OT Security Fundamentals? Send them this one.