A cement plant analyst has isolated a compromised historian but finds the attacker also holds a shared engineering account. Which NIST SP 800-61 activity addresses that account?
- A.Eradication by rotating the shared credential
- B.Recovery by restarting the kiosk display servers
- C.Preparation by writing a new acceptable use policy
- D.Detection by adding another sensor span port
Why A is correct
Removing attacker footholds such as stolen credentials is eradication. Policy writing is preparation, adding sensors is detection and restarting displays does not remove the access path.
Know someone studying for OT Security Fundamentals? Send them this one.