GSEC Network Security Devices Practice Question
A utility company must protect a SCADA network that uses proprietary Modbus/TCP communications on a segmented OT VLAN. The security team wants to block unauthorized function codes while allowing a small set of approved read operations, and it cannot tolerate latency or protocol-breaking behavior. Which control is MOST appropriate?
⚠ Common exam trap
The trap here is assuming that restricting traffic to TCP port 502 secures Modbus, when that port carries both benign reads and dangerous write or diagnostic function codes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An industrial protocol-aware firewall or IPS module that performs deep packet inspection of Modbus/TCP function codes.
Enforcing an allowlist of Modbus/TCP function codes requires inspecting the protocol payload, which only a control-system-aware firewall or IPS can do reliably. Port-based filtering cannot separate reads from writes because all Modbus/TCP operations share the same transport port.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A web application firewall placed in front of the SCADA historian's HTTP interface.
Why it's wrong here
A WAF protects HTTP-based applications and has no visibility into Modbus/TCP function codes or register semantics, so it cannot enforce the required allowlist. Deploying one may be useful for the historian's web console, but it does nothing for the proprietary control traffic the scenario is concerned about.
- ✓
An industrial protocol-aware firewall or IPS module that performs deep packet inspection of Modbus/TCP function codes.
Why this is correct
Deep packet inspection that understands Modbus/TCP can parse the function code field and enforce an allowlist of approved read operations while dropping others, which matches the requirement to block unauthorized function codes. Because it is purpose-built for OT protocols, it can do this without the latency and compatibility problems a general-purpose proxy would introduce.
- ✗
An email and web gateway performing TLS interception on the OT VLAN.
Why it's wrong here
A secure web gateway targets user browsing and mail flows, not industrial control protocols, and TLS interception is irrelevant to Modbus/TCP, which is typically unencrypted. Placing such a device on the OT VLAN would add latency and complexity without providing any function-code enforcement.
- ✗
A stateless packet filter permitting only TCP port 502 between the engineering workstation and the PLC.
Why it's wrong here
Port 502 is the transport for all Modbus/TCP traffic, so permitting it allows every function code, including write and diagnostic operations the team wants to block. A stateless filter also cannot see inside the payload, meaning it cannot distinguish an approved read from a dangerous write on the same port.
Visual reference
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.