A pharma plant operator notices a trend on the historian that does not match the batch recipe. Which detection source has just raised the concern?
- A.A historian anomaly
- B.A SIEM logon alert on the domain
- C.A firewall deny log spike
- D.An IDS signature hit on the DMZ
Why A is correct
Process data in the historian that deviates from the expected behavior is a classic OT detection source, since attacks on logic or setpoints change process values. The other sources track network, mail or door events.
Know someone studying for OT Security Fundamentals? Send them this one.