
EC-CouncilCertified Ethical Hacker
Domain 7Objective 5
OT and SCADA Attacks CEH Practice Questions (Page 10)
Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 46–50
- 46
A security consultant is reviewing the OT network of a food processing plant. The plant uses a mix of Ethernet/IP and DeviceNet protocols. The consultant discovers that the engineering workstation has a dual-homed NIC, one connected to the corporate network and one to the OT network. This configuration is a risk because it:
Select an answer first - 47
A security team is analyzing the Stuxnet attack to understand how it targeted SCADA systems. They note that Stuxnet exploited a zero-day vulnerability in Windows and then used a rootkit to hide its presence on the HMI, while also modifying the PLC logic. Which aspect of Stuxnet's TTPs is most characteristic of a targeted OT attack?
Select an answer first - 48
A penetration tester is performing an assessment of a water treatment facility. The tester has gained access to the corporate network and is now trying to move into the OT network. The OT network is protected by a firewall that only allows traffic from a specific patch management server. Which technique would the tester most likely use to gain access to the OT network?
Select an answer first - 49
A security consultant is assessing a wind farm's SCADA system. The turbines communicate with the central control center via a microwave link, and the control center is connected to the corporate network. The consultant identifies that the microwave link is unencrypted and can be intercepted. Which control would best mitigate the risk of an attacker intercepting and modifying turbine control commands?
Select an answer first - 50
Which attack vector involves an attacker gaining access to an OT/SCADA system by compromising a third-party vendor that provides software or hardware to the industrial facility?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.