
EC-CouncilICS/SCADA Cybersecurity
Domain 8Objective 5
Detecting Intrusions ICSSCADA Practice Questions (Page 6)
Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
5concepts
Questions 26–30
- 26
A security team is evaluating detection technologies for a wastewater treatment facility. The environment has a highly predictable traffic pattern: the same set of PLCs polling the same registers at fixed intervals. The team is concerned about zero-day attacks and insider threats that do not match known signatures. Which detection methodology is best suited for this environment?
Select an answer first - 27
An IDS at a chemical plant generates an alert for a DNP3 packet with a function code that is not in the standard DNP3 specification. The source IP is a newly installed intelligent electronic device (IED) from a vendor that has been used in other plants. The analyst checks the vendor's documentation and finds the function code is a proprietary extension. However, the analyst also notices that the IED is sending this function code to a PLC that is not from the same vendor. What is the most appropriate response?
Select an answer first - 28
After confirming that an IDS alert corresponds to a real intrusion attempt on a control system, what is the most appropriate immediate response action?
Select an answer first - 29
An IDS at a water utility generates an alert for a series of Modbus read requests from a known engineering workstation to a PLC. The requests are for register addresses that are not typically accessed by this workstation. The analyst reviews the workstation's recent activity and finds that a new software tool was installed yesterday for a scheduled maintenance task. What is the most appropriate action?
Select an answer first - 30
A pharmaceutical company is deploying an IDS in its ICS environment. The environment includes a batch process control system that uses a proprietary protocol. The security team is concerned about both known attacks and zero-day exploits. They also need to minimize false positives to avoid alert fatigue among the operators who monitor the IDS. Which combination of detection methodologies is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.