Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 3Objective 5

How ICS/SCADA Are Targeted ICSSCADA Practice Questions (Page 7)

Part of the Introduction to Hacking ICS/SCADA domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
6concepts

Questions 31–35

  1. 31application · medium

    A security team is reviewing the 2015 Ukrainian power grid attack to improve their own defenses. They note that the attackers gained access via phishing, then used VPN credentials to reach the SCADA network, and then used a remote access tool to open breakers. Which defense would have been most effective in preventing the final breaker operation?

    Select an answer first
  2. 32foundation · easy

    Which type of threat actor is most likely to conduct a politically motivated attack on an ICS/SCADA system?

    Select an answer first
  3. 33expert · hard

    An incident responder is analyzing a cyberattack on a manufacturing plant. The attacker first compromised a vendor's remote access account, then used that access to move laterally to the engineering workstation, and then reprogrammed a PLC to cause physical damage. The plant has no network segmentation and no monitoring on the OT network. Which improvement would have been most effective in detecting the attack at an earlier stage?

    Select an answer first
  4. 34application · medium

    A municipal water treatment plant has a control system that is not connected to the internet. However, a vendor technician recently plugged a laptop into the OT network to perform maintenance. The laptop had been used on other customer sites. Which attack vector is most likely to be exploited?

    Select an answer first
  5. 35application · medium

    A security consultant is studying the Stuxnet attack to advise a nuclear facility. The consultant notes that Stuxnet spread via USB drives and then modified the speed of centrifuges while reporting normal readings. Which attack vector and lifecycle stage are most relevant to this case?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.