How can defense in depth be achieved via security zones?
A.
By having zones within zones, or subzones, that provide layered security
B.
By having a zone edge that is using the security policies of the asset owner
C.
By having zones that are connected via conduits using the latest version of SSL
D.
By having zones that separate sensors from actuators, that provide layered security
The Answer Is:
A
This question includes an explanation.
Explanation:
ISA/IEC 62443 defines “defense in depth” as a layered approach to security. This can be accomplished by implementing zones within zones (sometimes called subzones), where each zone or subzone provides an additional security barrier or control layer. This segmentation restricts an attacker's ability to move laterally and ensures that compromise of one zone does not automatically result in compromise of the entire system.
[Reference: ISA/IEC 62443-1-1:2007, Section 4.3.3 (“Zones and Conduits”); ISA/IEC 62443-3-2:2020, Section 4.4.3 (“Layered security using zones and subzones”)., , ]
ISA-IEC-62443 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"