Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 7Objective 2

OT and SCADA Penetration Testing CPENT Practice Questions (Page 7)

Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.

51questions here
11free pages
10concepts

Questions 31–35

  1. 31application · medium

    A tester is enumerating a SCADA system that uses the OPC protocol for communication between the HMI and data historians. The tester wants to identify OPC servers and their exposed tags. Which technique is most appropriate?

    Select an answer first
  2. 32expert · hard

    A penetration tester has compromised a domain controller in the IT network of a utility company. The OT network is separated by a firewall that only allows specific IPs and ports, and the tester has no direct access to the OT network. The goal is to reach a historian server in the OT network. Which approach is the most likely to succeed?

    Select an answer first
  3. 33application · medium

    A penetration tester is mapping an OT network for a chemical plant. The plant uses a Purdue model with Level 0 (field devices), Level 1 (PLC), Level 2 (HMI), Level 3 (site operations), and Level 4 (enterprise IT). The tester has access to the IT network and wants to discover OT devices without crossing into the OT zones. Which technique best achieves this?

    Select an answer first
  4. 34application · medium

    During a threat modeling exercise for a power utility, the tester identifies that the DNP3 protocol is used between the master station and remote terminal units (RTUs). The tester notes that DNP3 supports unsolicited responses and that the RTUs are on a shared broadcast domain. Which attack vector should be prioritized in the threat model?

    Select an answer first
  5. 35expert · hard

    A penetration tester is planning an active scan of a live OT network at a wastewater treatment plant. The plant uses a mix of Modbus and DNP3 protocols. The tester must identify all live hosts and open ports, but the safety team has mandated that no packet should be sent that could be interpreted as a write command. Which scanning strategy best balances safety and effectiveness?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.