A firewall with deep packet inspection must let a historian poll a PLC over Modbus TCP yet stop any change to outputs. Which rule design achieves this?
- A.Allow codes 3 plus 6 from the historian to keep setpoints fresh
- B.Allow read codes 1 to 4 from the historian then deny the rest
- C.Allow TCP 502 from any source with unit ID filtering at the PLC
- D.Permit codes 1 to 16 from the historian with full logging enabled
Why B is correct
A DPI firewall can inspect the Modbus function code. Permitting only read codes 1 to 4 from the single historian address blocks coil and register writes (5, 6, 15, 16). Code 6 is a write, and allowing any source or logging alone does not stop changes.
Know someone studying for OT Security Fundamentals? Send them this one.