Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 7Objective 5

OT and SCADA Attacks CEH Practice Questions (Page 3)

Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
7concepts

Questions 11–15

  1. 11expert · hard

    A security researcher is analyzing a new malware strain found in a SCADA environment. The malware spreads via USB drives and uses a stolen digital certificate to sign its driver. It also contains modules that specifically target Siemens PLCs and can rewrite their logic. Which combination of TTPs is most indicative of a state-sponsored OT attack?

    Select an answer first
  2. 12expert · hard

    A security analyst is studying the Stuxnet attack to improve the organization's defenses. The analyst notes that Stuxnet used a man-in-the-middle attack to intercept and modify communications between the HMI and PLCs. Which defensive control would be most effective in detecting this type of attack?

    Select an answer first
  3. 13application · medium

    A water treatment facility uses a legacy SCADA system with Modbus TCP between the PLCs and the HMI. The OT network is isolated from the corporate IT network by a firewall, but the firewall allows any traffic from the IT network to reach the OT network on port 502. During a security assessment, you discover that the PLCs accept writes from any host that can reach them. Which control would most directly reduce the risk of an attacker on the IT network modifying PLC setpoints?

    Select an answer first
  4. 14application · medium

    A security team is studying the 2015 Ukraine power grid attack to improve their own OT defenses. They note that the attackers gained access to the corporate network via phishing, then moved laterally to the OT network, and finally used the HMI to open breakers. Which control would have been most effective in preventing the final disruptive action?

    Select an answer first
  5. 15application · medium

    A security analyst is investigating a breach at a power utility. The analyst finds that the initial compromise occurred through a vendor's remote maintenance account, which had weak credentials and was not protected by MFA. The attacker used this account to access the OT network and modify control logic. Which attack vector best describes this incident?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.