
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 2
OT and SCADA Penetration Testing CPENT Practice Questions (Page 2)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
51questions here
11free pages
10concepts
Questions 6–10
- 6
A penetration tester is conducting passive reconnaissance on a hospital's building management system (BMS) that controls HVAC and elevators. The tester has access to a SPAN port on the BMS network switch. Which of the following is the most effective passive technique to identify the BMS controllers and their firmware versions?
Select an answer first - 7
In the context of OT network architecture, what is the primary purpose of a 'zone'?
Select an answer first - 8
In an OT penetration test, what is 'pivoting'?
Select an answer first - 9
After completing an OT penetration test, the tester must write a report for both technical staff and plant management. The report includes a critical vulnerability in a PLC that could allow remote shutdown. What is the best way to present this finding to ensure both audiences understand the risk?
Select an answer first - 10
During an OT penetration test at a power utility, the tester identifies that the DNP3 protocol is used between the control center and remote substations. The tester wants to model threats that could cause a denial of service to the substation communications. Which threat modeling approach is most appropriate to identify specific DNP3-related attack vectors?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.