A report lists the following: a phishing mail yields a vendor VPN session, the adversary reaches the engineering workstation, modified logic is downloaded to a PLC, then alarms are suppressed. Which tactic order fits?
- A.Initial Access then Lateral Movement then Execution then Inhibit Response Function
- B.Discovery then Initial Access then Collection then Impair Process Control
- C.Lateral Movement then Initial Access then Inhibit Response Function then Execution
- D.Impair Process Control then Initial Access then Evasion then Lateral Movement
Why A is correct
Phishing into a VPN is Initial Access, reaching the workstation is Lateral Movement, downloading logic is Execution, and suppressing alarms is Inhibit Response Function. The other orders place later stages before entry or mislabel the steps.
Know someone studying for OT Security Fundamentals? Send them this one.