
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 2
OT and SCADA Penetration Testing CPENT Practice Questions (Page 8)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
51questions here
11free pages
10concepts
Questions 36–40
- 36
A penetration tester is reviewing the OT network architecture of a food processing plant. The plant has a DMZ between the IT and OT networks, but the tester finds that the firewall rules allow any-to-any communication between the DMZ and the OT control network. What is the most critical recommendation to improve the security posture?
Select an answer first - 37
What is the role of a 'conduit' in an OT network architecture?
Select an answer first - 38
A penetration tester is assessing a manufacturing plant that has a flat OT network with no segmentation between the HMI, PLCs, and a wireless access point used by maintenance engineers. The tester has compromised the wireless access point. Which attack path is the most likely to succeed in reaching the PLCs?
Select an answer first - 39
A penetration tester has compromised a workstation in the IT network of a manufacturing company. The tester needs to pivot to the OT network to reach a PLC. The OT network is segmented with a firewall that only allows specific IPs and ports. Which approach is most likely to succeed while minimizing detection?
Select an answer first - 40
A penetration tester has identified that a PLC is using a default password for its web interface. The tester wants to exploit this to gain access to the PLC's configuration. What is the most important consideration before attempting to log in?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.