
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 2
OT and SCADA Penetration Testing CPENT Practice Questions (Page 3)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
51questions here
11free pages
10concepts
Questions 11–15
- 11
A penetration tester has completed an OT assessment and found a critical vulnerability in a DNP3 implementation that could allow an attacker to send false control commands to a power grid substation. The client wants to know the risk in business terms. The tester must produce a report that is useful for both the CISO and the plant engineer. Which approach is most effective?
Select an answer first - 12
A penetration tester has completed an assessment of a natural gas pipeline's SCADA system. The final report needs to communicate risks to both technical and executive audiences. Which report structure best achieves this?
Select an answer first - 13
Which of the following is a common attack surface in an OT/SCADA environment?
Select an answer first - 14
A penetration tester has found a vulnerability in a Modbus TCP implementation that allows an attacker to write to arbitrary registers. The PLC controls a cooling system. The tester wants to demonstrate the impact without causing physical damage. Which action is the safest way to demonstrate the vulnerability?
Select an answer first - 15
A junior penetration tester is joining an OT assessment for a food processing plant. The lead tester explains that OT networks prioritize availability and safety over confidentiality, and that the plant uses a mix of legacy serial protocols and modern Ethernet. Which statement best describes a key difference the junior tester should understand?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.