Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 8Objective 5

Detecting Intrusions ICSSCADA Practice Questions (Page 3)

Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts

Questions 11–15

  1. 11foundation · easy

    Which intrusion pattern is specifically associated with unauthorized commands sent to a PLC (Programmable Logic Controller) over an industrial network?

    Select an answer first
  2. 12application · medium

    A security architect is designing an IDS solution for a pharmaceutical manufacturing facility. The facility has a mix of modern and legacy PLCs, some of which use proprietary protocols. The team wants to detect both known attacks and unusual behavior without overwhelming the analysts with alerts. Which approach best balances these requirements?

    Select an answer first
  3. 13application · medium

    A manufacturing company is deploying an IPS to protect its PLCs from known exploits. The network uses a standard three-tier architecture: Level 3 (site operations), Level 2 (supervisory control), and Level 1 (basic control). The security team wants to block malicious traffic before it reaches the PLCs. Where should the IPS be placed to be most effective?

    Select an answer first
  4. 14expert · hard

    A security architect is selecting an IDS for a large water distribution network with hundreds of remote pumping stations connected via a WAN. The traffic patterns are highly variable due to seasonal demand and maintenance schedules. The team needs to detect both known attacks and unusual behavior, but the analyst team is small and cannot handle a high volume of false positives. Which detection methodology should be the primary approach?

    Select an answer first
  5. 15expert · hard

    A security analyst at a nuclear facility is reviewing IDS alerts and finds a series of alerts for Modbus TCP writes to a single register on a cooling pump PLC. The writes are incrementing the register value by 1 every few seconds. The engineering team confirms that the register is not used for any normal control function and is not mapped in the HMI. The source IP is a rarely used maintenance laptop. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.