Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 7Objective 2

OT and SCADA Penetration Testing CPENT Practice Questions (Page 1)

Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.

51questions here
11free pages
10concepts

Questions 1–5

  1. 1application · medium

    A penetration tester is planning an active scan of a live electrical substation's OT network. The substation uses legacy devices that are known to be sensitive to network traffic. Which mitigation strategy should be included in the test plan?

    Select an answer first
  2. 2foundation · easy

    What is a key difference between a penetration testing report for an OT environment and one for a traditional IT environment?

    Select an answer first
  3. 3foundation · easy

    Which of the following is a key difference between traditional IT networks and OT/SCADA networks?

    Select an answer first
  4. 4application · medium

    A tester is performing active enumeration of a SCADA network that uses Modbus TCP. The tester needs to identify all PLCs and their register maps without causing a PLC to enter a fault state. Which approach minimizes the risk of disruption?

    Select an answer first
  5. 5expert · hard

    A penetration tester is developing a threat model for a smart grid environment. The environment includes a control center, substation RTUs, and a wide-area network using DNP3. The tester needs to identify the most likely attack path that could lead to a blackout. Which of the following is the most critical attack surface to consider?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.