
EC-CouncilICS/SCADA Cybersecurity
Domain 6Objective 2
Establishing Policy - ISO Roadmap ICSSCADA Practice Questions (Page 6)
Part of the Securing the ICS Network domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 26–30
- 26
A chemical plant has a legacy SCADA system that cannot be patched. The plant must comply with ISO 27001 and is developing a roadmap. What is the most appropriate action to address the patching gap?
Select an answer first - 27
A transportation authority is establishing an ICS security policy based on ISO/IEC 27001. The policy must be reviewed and updated regularly. Which governance process BEST ensures the policy remains current and effective?
Select an answer first - 28
Which component is typically included in an ICS security policy document?
Select an answer first - 29
A regional water utility is implementing ISO/IEC 27001 and has selected the relevant ISO/IEC 27002 controls. During the risk assessment, the team identifies that a legacy PLC on the plant network cannot be patched and has a known remote-code-execution vulnerability. The control selection must address this risk without causing operational downtime. Which control approach best aligns with the ISO framework in this scenario?
Select an answer first - 30
Which ISO/IEC 27001 requirement may need special interpretation when applied to ICS/SCADA due to legacy systems?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.