ISA IC34 ISA-IEC 62443 Cybersecurity Design Specialist - IC34 ISA-IEC 62443 Cybersecurity Design Specialist Exam
Page: 3 / 20
Total 100 questions
Question #11 (Topic: Exam A)
Network segmentation and DMZs belong to which Foundational Requirement?
A. FR 3 - System integrity (SI)
B. FR 4 - Data confidentiality (DC)
C. FR 5 - Restricted Data Flow (RDF)
D. FR 7 - Resource availability (RA)
Answer: C
Question #12 (Topic: Exam A)
Who is accountable for the security of an IACS?
A. The asset owner
B. The product supplier
C. The integration provider
D. The maintenance provider
Answer: A
Question #13 (Topic: Exam A)
Which of the following should be installed as a best practice for protecting IACS devices?
A. A firewall with deep packet inspection capabilities
B. A firewall rule allowing unrestricted traffic on ports 0 through 65,535
C. Simple Network Management Protocol Version 1 (SNMPv1) with encryption enabled
D. An intrusion detection system (IDS) with rate limiting turned on
Answer: A
Question #14 (Topic: Exam A)
Which is a best practice for device hardening in an IACS?
A. Ignore vendor-specific security guidance.
B. Add network interfaces for ease of maintenance.
C. Enable Hypertext Transfer Protocol (HTTP) access on port 80.
D. Disable remote program changes on programmable logic controllers (PLCs).
Answer: D
Question #15 (Topic: Exam A)
Which statement is TRUE with regards to network segments?
A. There cannot be a router inside a zone.
B. All assets have a different Subnet mask.
C. A DMZ is a three-tier network segmentation.
D. There can only be one (1) segment per zone.
Answer: C