Skip to content
ScopefileGet the app

Technique fileIoT and OT hacking

IT vs OT security: why the priorities flip

IT security protects data, so confidentiality usually leads; OT security protects physical processes, so safety and availability lead and confidentiality comes last. Plants run equipment for decades, on protocols designed for trusted networks, where an outage can hurt people. Module 18 builds its OT material on that flipped order.

Exam
312-50
Domain
7 · Mobile, IoT, OT
Targets
8

OT vocabulary

OT
Operational technology: hardware and software that monitor and control physical equipment and processes.
ICS
Industrial control system, the umbrella term for SCADA, DCS and the controllers beneath them.
SCADA
Supervisory control and data acquisition: central supervision of equipment spread across a wide area, such as a pipeline or a power grid.
DCS
Distributed control system: process control concentrated in one plant, such as a refinery.
PLC
Programmable logic controller: a rugged computer that runs control logic for machinery.
RTU
Remote terminal unit: a field device that links remote equipment to a SCADA system.
HMI
Human-machine interface: the screen operators use to watch and adjust the process.
Historian
A database that records process data over time for operations and reporting.
IIoT
Industrial IoT, the connected sensors and devices behind IT/OT convergence.

Same words, different priorities

How IT and OT environments weigh the same security concerns
ConcernITOT
First priority (differs)Confidentiality of dataSafety of people and equipment
Priority order (differs)Confidentiality, integrity, availabilityAvailability and integrity before confidentiality
Worst outcome (differs)Data breachPhysical harm, outage, environmental damage
Patching (differs)Routine and frequentRare, planned with operations, often vendor-approved
Equipment life (differs)Replaced every few yearsRuns for decades
Protocols (differs)Mostly modern and encryptedDesigned for closed, trusted networks
Monitoring (differs)Active scanning is routinePassive monitoring is preferred
Needs written authorization to testYesYes

Tinted rows marked ≠: the two differ.

Where the IT/OT boundary sits

Zones of the Purdue reference model, from the control zone up to the enterprise, with the industrial DMZ between them
Zones of the Purdue reference model, from the control zone up to the enterprise, with the industrial DMZ between themLevels 4-5enterprise ITIndustrial DMZIT/OT boundaryLevel 3site operationsLevels 0-2cell and area zone

How an authorized OT assessment stays safe

  1. Agree scope with operations

    Plant engineers and safety staff sign off on what may be touched and when, on top of the usual written authorization.
  2. Inventory from records and listening

    Asset lists come from documentation and from observing traffic already on the wire.
  3. Map the zones

    Look for paths that skip the industrial DMZ, such as vendor remote access or dual-homed engineering workstations.
  4. Test on a replica

    Anything intrusive runs against a lab copy or test bench, never a live controller.
  5. Leave it as you found it

    Remove every account, tool and connection added for the test, and confirm with operations that the system is back to its baseline.

Plant floor or server room?

Where parts sit on the Purdue model first, then judgment calls about handling a live plant.

Answered 0/8Hits 0

T-01

In an industrial control system (ICS) setup, which level of the Purdue Reference Model is designed to handle process sensing and includes devices such as sensors and actuators?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ALevel 2 is area supervisory control, where HMIs and SCADA servers oversee processes, not the sensors themselves.
  2. BLevel 1 holds the basic controllers, such as PLCs and RTUs, which read sensors and drive actuators but are not the field devices themselves.
  3. CLevel 3 covers site operations, such as historians and production scheduling, far above the physical process.
  4. DCorrect: Level 0 is the physical process, holding the sensors, actuators and other field devices that directly measure and change it.
T-02

In the Purdue Reference Model for industrial control systems (ICS), at which level are Human Machine Interface (HMI) devices typically located?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: Level 2, area supervisory control, holds HMIs and SCADA servers that operators use to monitor and control processes.
  2. BLevel 0 holds field devices such as sensors and actuators, not operator interfaces.
  3. CLevel 3 covers site-wide operations such as historians and production scheduling rather than direct operator control screens.
  4. DLevel 1 holds the controllers, such as PLCs, that run the control logic which HMIs supervise.
T-03

A security administrator deploys an aggressive, inline active vulnerability scanner across an industrial control system network. What is the MOST critical operational risk associated with this action?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: fragile controllers and real-time OT protocols can crash or miss timing under aggressive scanning, causing outages or unsafe physical conditions.
  2. BExtra log volume is a nuisance, but it is trivial compared with the risk of disrupting physical control processes.
  3. CScanners do not usually force cipher downgrades, and many OT protocols lack encryption entirely.
  4. DAlert noise can occur, but the most critical risk in OT is disrupting deterministic control and physical safety.
T-04

A critical infrastructure facility discovers a vulnerability with a Medium CVSS base score affecting a programmable logic controller. Why MUST the security team prioritize this flaw as Critical for remediation?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe CVSS v3.1 base score reflects intrinsic exploitability and impact, not hardware age.
  2. BNeeding high privileges lowers a vulnerability's severity, so it would not justify raising the priority.
  3. CCorrect: in OT, impact on safety and availability raises urgency, which CVSS v3.1 environmental metrics or frameworks like SSVC capture beyond the base score.
  4. DFull isolation would lower the urgency rather than raise it, although true isolation is rare in practice.
T-05

In the context of OT (Operational Technology) security, what is an air gap?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APLCs use scan cycles and timers, but an air gap is a network isolation concept, not a timing feature.
  2. BCorrect: an air gap physically separates a network from untrusted networks, although removable media and maintenance links can still bridge it.
  3. CAn air gap means having no wireless or wired connection, so it is the opposite of a transmission technology.
  4. DAn air gap is a protective design choice, not a protocol weakness, even though it can be undermined by removable media.
T-06

An engineering team must export real-time monitoring data from a critical operations network to a corporate IT environment. They require a control that physically guarantees nothing can flow back into the OT network. Which control fits this requirement?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: a data diode physically allows traffic in only one direction, so monitoring data can leave the OT network while nothing can flow back in.
  2. BA VPN encrypts traffic but still creates a two-way path into the OT network that attackers could use.
  3. CBidirectional proxies still permit return traffic, so they do not enforce a strict one-way boundary.
  4. DDeep packet inspection firewalls are software-defined and bidirectional, so they lack the deterministic one-way guarantee required here.
T-07

What is the most common vulnerability in SCADA systems that can be exploited in OT environments?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: many legacy ICS protocols such as Modbus and DNP3 were designed without authentication, so any device that can reach them can send commands.
  2. BWeak cryptography is a concern, but many SCADA protocols use no cryptography at all, which is the more fundamental gap.
  3. CMemory corruption bugs do occur in ICS software, but missing protocol authentication is the more pervasive weakness.
  4. DExcessive logging is not a common OT weakness; many systems actually suffer from too little logging and visibility.
T-08

A critical remote code execution vulnerability is disclosed for a PLC controlling a continuous manufacturing process. What is the MOST appropriate immediate response to mitigate the threat while maintaining operational safety?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: tightening segmentation and access controls reduces exposure now, while patching waits for a tested, planned maintenance window.
  2. BMoving real-time control logic to the cloud adds latency and new exposure, and it is not a realistic emergency response.
  3. CUntested firmware patches on a running process can cause failures or safety incidents, so OT patching needs testing and scheduling.
  4. DShutting down a controller for a continuous process can be costly and unsafe, so compensating controls are preferred until a planned fix.

In IT, downtime is an inconvenience. In OT, it can be the incident.

Where this sits in your prep

OT shares Module 18 with IoT, and the IoT and OT hacking module covers the IoT half. Together with mobile they form Domain 7, weighted at 10% in blueprint v5.0 (checked Oct 11, 2026).

Learn well

  • The flipped priority order.
  • The Purdue levels and which components belong at each one.
  • SCADA against DCS, and the roles of PLC, RTU and HMI.
  • Why the industrial DMZ exists and what should cross it.

Skim

  • Register maps and function codes of individual industrial protocols.
  • Vendor product lines and the names of OT malware families.

IT/OT convergence ties the module together: as plants connect sensors to cloud analytics and enterprise networks, the separation the Purdue model assumes gets thinner, and the boundary zone carries more of the load.

Sources