An enterprise security architecture team is deploying a deception and disruption strategy within an operational technology (OT) network to detect unauthorized lateral movement and internal service discovery. The environment includes legacy industrial control systems, programmable logic controllers (PLCs), and human-machine interfaces (HMIs). Which of the following implementation practices should the team select to achieve high-fidelity threat detection while preventing operational disruption to production systems? (Select TWO.)
- Deploying low-interaction honeypots on isolated subnets that emulate industrial control protocols to generate alerts upon any inbound connection attempt.Cevap
- Placing decoy credentials and fake network path references into administrative host memory to serve as breadcrumbs leading attackers toward decoy systems.Cevap
- CConfiguring low-interaction honeypots inline between production PLCs and network switches to filter unauthorized industrial protocol traffic in real time.
- DDeploying active vulnerability scanning software on deception nodes to automatically execute remediation scripts on production PLCs when probes occur.
Cevap
The correct practices are deploying low-interaction honeypots on isolated subnets that emulate industrial control protocols and placing decoy credentials or network references in administrative host memory as breadcrumbs.
Deploying low-interaction honeypots on isolated subnets that emulate industrial protocols provides a safe, non-intrusive method for capturing unauthorized network discovery in OT environments without placing real hardware at risk. Furthermore, placing decoy credentials and fake path references in host memory acts as breadcrumbs that steer adversaries away from production assets and into monitored deception traps during lateral movement.
Adım Adım Çözüm
Anahtar Kavram
Deception and Disruption Architecture in Specialized Networks