
EC-CouncilICS/SCADA Cybersecurity
Domain 3Objective 6
Attack Methodologies in ICS ICSSCADA Practice Questions (Page 5)
Part of the Introduction to Hacking ICS/SCADA domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
5concepts
Questions 21–25
- 21
A water treatment plant uses a radio-based SCADA system. An attacker with a software-defined radio (SDR) is able to intercept and retransmit control commands to open a valve. Which attack methodology is being used, and what is the most effective mitigation?
Select an answer first - 22
A security analyst is studying the 2010 Stuxnet attack. The analyst notes that Stuxnet used a MITM attack to intercept and modify communications between the PLC and the frequency converters, while also spreading via USB drives. Which combination of attack methodologies and vectors does this case study illustrate?
Select an answer first - 23
Which attack methodology involves capturing a valid command and retransmitting it later to cause the same effect?
Select an answer first - 24
In the 2015 Ukraine power grid attack, attackers used spear-phishing to deliver BlackEnergy malware, then used stolen VPN credentials to access the SCADA network, and finally opened breakers remotely. Which phases of the ICS attack lifecycle are demonstrated in this case study?
Select an answer first - 25
Which of the following is a common human-based attack vector used to compromise an ICS/SCADA environment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.