A passive sensor watches OPC UA sessions that are signed and encrypted. What can the sensor still collect?
- A.Method call arguments written to the server
- B.Endpoint addresses plus session timing metadata
- C.Node values read by each connected client
- D.The address-space tree of the server
Why B is correct
Encryption hides payload content such as node values and method arguments, but IP addresses ports and timing remain visible on the wire. That metadata still supports inventory and baselining.
Know someone studying for OT Security Fundamentals? Send them this one.