Attackers modify installer packages hosted on an automation vendor's download page so engineers unknowingly deploy a trojan. Which initial access idea is this?
- A.Replication through removable media on laptops
- B.Rogue master injecting commands on a fieldbus
- C.Exploitation of a public web server at the plant
- D.Supply chain compromise of trusted software
Why D is correct
Poisoning software that customers already trust is a supply chain compromise, the route used by the Havex campaign. The other options describe direct exploitation of a plant server, USB-borne spread, and protocol-level command injection.
Know someone studying for OT Security Fundamentals? Send them this one.