A Modbus TCP session captured on the plant network is replayed days later against the PLC and the write executes. Which missing property made this possible?
- A.No message authentication or freshness check in the protocol
- B.Missing write function codes in the published protocol specification
- C.Missing TCP handshake before the application payload data flows
- D.Missing transaction ID field in the MBAP header definition
Why A is correct
Modbus carries no signature, nonce, or timestamp, so a valid frame stays valid forever. The MBAP header does have a transaction ID, writes exist as codes 5, 6, 15, and 16, and TCP does handshake, but none of those prove freshness.
Know someone studying for OT Security Fundamentals? Send them this one.