Question 1
Q1Multiple answersWhich of the following will MOST likely adversely impact the operations of unpatched traditional programmable-logic controllers, running a back-end LAMP server and OT systems with human- management interfaces that are accessible over the Internet via a web interface? (Choose two.)
Show answer & explanation
Correct answers: D, F
Weak encryption is a critical vulnerability for unpatched programmable logic controllers and OT systems accessible over the internet, as these legacy systems often use outdated or no encryption protocols, making them vulnerable to man-in-the-middle attacks and data interception. Server-side request forgery (SSRF) is also highly impactful as the LAMP server backend can be exploited to make unauthorized requests to internal OT systems.
Server-side request forgery (SSRF) attacks are particularly dangerous for LAMP servers managing OT systems, as attackers can exploit the web interface to make internal requests to programmable logic controllers and other industrial systems. Combined with weak encryption on unpatched systems, SSRF can lead to complete compromise of operational technology infrastructure.