
EC-CouncilCertified Cybersecurity Technician
Domain 4Objective 4
IoT and OT Security CCT Practice Questions (Page 9)
Part of the Cloud, Wireless, Mobile, and IoT/OT Security domain, which makes up ~17% of our current practice bank.
51questions here
11free pages
12concepts
Questions 41–45
- 41
An engineer is reviewing the network architecture of a power utility that follows the Purdue model. The engineer notices that a workstation in the control center (Level 3) is able to directly communicate with a field device on the process network (Level 0) using DNP3. What is the primary security concern with this architecture?
Select an answer first - 42
A global manufacturer operates OT facilities in multiple countries. They must comply with both IEC 62443 and local data residency regulations. The company wants to implement a centralized security monitoring solution. Which approach best satisfies both requirements?
Select an answer first - 43
A cybersecurity analyst is investigating a suspected intrusion in a natural gas pipeline's OT network. The analyst finds that an attacker gained access to a human-machine interface (HMI) and sent unauthorized commands to a programmable logic controller (PLC) using the Modbus protocol. Which mitigation would have been most effective in preventing this specific attack?
Select an answer first - 44
A water treatment facility uses a legacy SCADA system that relies on Modbus TCP to communicate between a control server and remote terminal units (RTUs). The facility's network team wants to reduce the risk of an attacker sending malicious commands to the RTUs. Which control is most effective without requiring replacement of the legacy equipment?
Select an answer first - 45
Which standard is specifically developed for the security of industrial automation and control systems (IACS)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.