Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 8Objective 5

Detecting Intrusions ICSSCADA Practice Questions (Page 1)

Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts

Questions 1–5

  1. 1foundation · easy

    In an ICS/SCADA environment, what is the primary role of an intrusion detection system (IDS)?

    Select an answer first
  2. 2expert · hard

    An analyst at a manufacturing plant is reviewing IDS alerts and sees a high-priority alert for a known exploit targeting a specific PLC model. The alert is triggered by traffic from an engineering workstation to a PLC. The engineering team confirms that the workstation is used for programming and has the latest antivirus. The PLC is a model that is not in the plant's asset inventory. What is the most appropriate action?

    Select an answer first
  3. 3application · medium

    An IDS at a wastewater treatment plant detects a series of CIP (Common Industrial Protocol) packets where the source and destination IP addresses are the same. The packets are being sent to the PLC's EtherNet/IP port. What does this pattern most likely indicate?

    Select an answer first
  4. 4application · medium

    An IDS at a food processing plant generates an alert for a single abnormal packet sent to a PLC's configuration port. The packet contains a string of characters that matches a known exploit signature for a different type of device. The PLC is a legacy model that is not known to be vulnerable to this exploit. What is the most appropriate initial response?

    Select an answer first
  5. 5expert · hard

    An ICS security team is evaluating detection methodologies for a pipeline control system. The system has a well-defined and stable set of operations, but the team is concerned about insider threats from operators who have legitimate access. They are also concerned about sophisticated external attackers who may use valid credentials. The team needs a detection method that can identify malicious activity even when the activity uses valid commands and credentials. Which detection methodology is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.