Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 7Objective 5

OT and SCADA Attacks CEH Practice Questions (Page 7)

Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
7concepts

Questions 31–35

  1. 31application · medium

    An oil refinery has a SCADA network with legacy PLCs that cannot be patched. The corporate IT team wants to allow remote engineers to access the HMI for monitoring, but the security team insists on minimizing the attack surface. Which approach best balances the need for remote access with the constraint of unpatched legacy devices?

    Select an answer first
  2. 32expert · hard

    A security team is investigating an incident at a manufacturing plant where the production line was halted. The investigation reveals that an attacker gained access to the plant's business network via a phishing email, then used a legitimate remote desktop tool to jump to an engineering workstation, and finally sent unauthorized commands to a PLC using the engineering software. Which combination of controls would have been most effective in preventing this attack chain?

    Select an answer first
  3. 33foundation · easy

    Which attack on the Ukraine power grid is notable for using spear-phishing emails to deliver malware that allowed attackers to remotely open circuit breakers?

    Select an answer first
  4. 34expert · hard

    A utility company is planning to connect its OT network to a cloud-based monitoring service for predictive maintenance. The OT network uses legacy protocols and has limited bandwidth. The security team is concerned about exposing the OT network to the internet. Which architecture best balances the need for cloud monitoring with security?

    Select an answer first
  5. 35application · medium

    A security analyst is reviewing logs from a SCADA environment and notices that an attacker performed a port scan of the OT network, then used a default password to log into a PLC's web interface, and finally sent unauthorized commands to a pump. Which phase of the attack methodology does the use of the default password represent?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.