Which feature lets an ICS network IDS flag a Modbus write to a coil sent from an engineering laptop?
- A.Reputation scoring of external addresses on a threat feed
- B.Spectrum analysis of radio noise near wireless antennas
- C.Deep packet inspection of industrial protocol function codes
- D.Signature matching of cookies in web application sessions
Why C is correct
ICS-aware inspection parses the protocol and reads the function code and target, so it can see a write. Web, reputation and radio tools lack that protocol view.
Know someone studying for OT Security Fundamentals? Send them this one.