Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 8Objective 5

Detecting Intrusions ICSSCADA Practice Questions (Page 7)

Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts

Questions 31–35

  1. 31application · medium

    A chemical plant has a control network with multiple PLCs on a dedicated OT VLAN and a separate IT VLAN for business systems. A junction point connects the two VLANs through a stateful firewall. The security team wants to detect both external attacks from the IT side and internal misuse by operators on the OT side. They have two IDS sensors available. What is the most effective placement?

    Select an answer first
  2. 32application · medium

    An analyst notices an IDS alert for a series of EtherNet/IP packets from an engineering workstation to a PLC. The packets contain a CIP (Common Industrial Protocol) service code for 'Forward Open' that is being sent repeatedly to the same connection. The engineering team confirms they are not running any software that would generate this traffic. What is the most likely explanation for this alert?

    Select an answer first
  3. 33expert · hard

    A regional water utility has deployed an IDS with both signature-based and anomaly-based detection. The IDS is placed at the boundary between the IT and OT networks. Over the past week, the IDS has generated the following alerts: (1) a signature match for a known exploit targeting a Windows-based HMI, (2) an anomaly alert for a sudden increase in Modbus traffic to a PLC that normally has low traffic, and (3) an anomaly alert for a new OPC UA connection from an unknown IP. The analyst has limited time and must prioritize which alert to investigate first. The HMI is a critical asset, the PLC is a non-critical pump controller, and the OPC UA connection is to a data historian. Which alert should be investigated first?

    Select an answer first
  4. 34foundation · easy

    Which of the following is a common attack vector targeting ICS/SCADA protocols such as Modbus or DNP3?

    Select an answer first
  5. 35application · medium

    A security analyst at a power utility is reviewing IDS alerts and notices a high volume of alerts triggered by a rule that flags any Modbus TCP packet with the function code 90 (0x5A), which is not a standard Modbus function code. The engineering team confirms that a legacy PLC model in the plant uses this code for a proprietary diagnostic command during normal maintenance. What is the most appropriate action for the analyst to take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.