Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 8Objective 3

Advantages and Limitations of IDS ICSSCADA Practice Questions (Page 3)

Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
3concepts

Questions 11–15

  1. 11application · medium

    A power utility is evaluating IDS deployment for its substation networks. The team notes that encrypted protocols are increasingly used between modern RTUs. What is the most significant limitation this introduces for a network-based IDS?

    Select an answer first
  2. 12expert · hard

    A water utility has deployed a network-based IDS that uses deep packet inspection (DPI) for Modbus TCP. During peak flow periods, the IDS drops packets because the CPU is saturated. The team must maintain detection accuracy without upgrading hardware. What is the most effective mitigation?

    Select an answer first
  3. 13expert · hard

    A utility company is required to demonstrate to regulators that it has visibility into its OT network. The team has a limited budget and must choose between a commercial IDS with vendor support and an open-source IDS with in-house expertise. Which factor is most important in this decision?

    Select an answer first
  4. 14application · medium

    A food and beverage manufacturer has a mix of modern and legacy PLCs. The security team wants to deploy a network-based IDS, but the network team warns that some switches do not support SPAN ports. What is the most practical alternative to gain visibility?

    Select an answer first
  5. 15expert · hard

    A natural gas pipeline company has a network IDS that monitors the control network. They want to use the IDS to support incident response and forensic investigations. However, the IDS only stores alert metadata, not full packet captures. What is the best way to address this limitation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.