Stuxnet carried several exploits yet activated its payload only on controllers matching a specific configuration. What conclusion about the operation follows?
- A.It aimed to maximize infections across the internet
- B.It was a random worm with accidental effects on plants
- C.It was engineered for a specific physical target
- D.It relied on operators to choose victims
Why C is correct
Checking for a particular controller and drive setup before acting shows knowledge of the victim plant and deliberate targeting. A random worm would fire everywhere, and operators had no role in selecting victims.
Know someone studying for OT Security Fundamentals? Send them this one.