Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 7Objective 2

OT and SCADA Penetration Testing CPENT Practice Questions (Page 6)

Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.

51questions here
11free pages
10concepts

Questions 26–30

  1. 26foundation · easy

    Why is it important to exploit OT vulnerabilities in a 'controlled manner' during a penetration test?

    Select an answer first
  2. 27application · medium

    A tester is assessing a wind farm that uses OPC UA for communication between the SCADA server and wind turbine controllers. The tester wants to enumerate the OPC UA server endpoints and data points without disrupting the process. Which tool or technique is most appropriate?

    Select an answer first
  3. 28foundation · easy

    Which of the following is a mitigation strategy to reduce the operational impact of active scanning on a live OT network?

    Select an answer first
  4. 29foundation · easy

    Which of the following is an example of an actionable remediation recommendation in an OT penetration testing report?

    Select an answer first
  5. 30application · medium

    A penetration tester is performing reconnaissance on a manufacturing plant's OT network. The plant uses a Purdue Model with Level 3 (site operations) and Level 2 (control systems) separated by a firewall. The tester has access to a workstation on Level 3. Which technique is most appropriate to discover Level 2 devices without crossing the firewall?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.