A new security engineer must build an asset inventory for a refinery whose legacy controllers are fragile. Which discovery approach is the safest starting point?
- A.A credentialed vulnerability scan of each PLC at shift change
- B.A full TCP port sweep from the engineering workstation
- C.Passive capture of mirrored switch traffic to fingerprint devices
- D.Polling each IP address with Modbus diagnostic requests
Why C is correct
Passive capture listens to copies of traffic and sends nothing to controllers, so it cannot disturb a fragile device. Scans, port sweeps and diagnostic polling put unexpected packets on the wire and have crashed older network stacks.
Know someone studying for OT Security Fundamentals? Send them this one.