Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 3Objective 6

Attack Methodologies in ICS ICSSCADA Practice Questions (Page 2)

Part of the Introduction to Hacking ICS/SCADA domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts

Questions 6–10

  1. 6foundation · easy

    The 2010 Stuxnet attack is a well-known ICS/SCADA case study. Which of the following best describes a key methodology used in that attack?

    Select an answer first
  2. 7application · medium

    A security consultant is assessing a pipeline control system. She identifies that the HMI software has a known vulnerability that allows remote code execution, and that the engineering workstation uses default credentials. Which attack surfaces are most directly exposed?

    Select an answer first
  3. 8application · medium

    A food processing plant has a wireless network for temperature sensors. An attacker sits in the parking lot and captures the wireless traffic, then replays it to spoof a sensor reading. Which attack vector is being used?

    Select an answer first
  4. 9application · medium

    During an incident response review, a security analyst discovers that an attacker first gained access to the corporate IT network, then pivoted to the ICS DMZ, and finally reached the HMI network. The attacker used a spear-phishing email to obtain initial credentials. Which phase of the ICS attack lifecycle does the spear-phishing email represent?

    Select an answer first
  5. 10application · medium

    A security team is analyzing the 2015 Ukraine power grid attack. They note that the attackers used spear-phishing to gain access to the corporate network, then used VPN credentials to reach the ICS network, and finally issued remote commands to open breakers. Which combination of attack methodologies and lifecycle phases does this case study illustrate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.