
EC-CouncilICS/SCADA Cybersecurity
Domain 3Objective 5
How ICS/SCADA Are Targeted ICSSCADA Practice Questions (Page 8)
Part of the Introduction to Hacking ICS/SCADA domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
6concepts
Questions 36–40
- 36
A security team is studying the Stuxnet attack to improve their defense strategy. They note that Stuxnet spread through USB drives and exploited a zero-day vulnerability in Windows, then targeted specific Siemens PLCs to alter centrifuge speeds. Which lesson is most directly applicable to defending modern ICS?
Select an answer first - 37
What is a primary motivation for attackers targeting ICS/SCADA systems?
Select an answer first - 38
A chemical plant has a legacy serial-based RTU that is not patchable, connected to a modern TCP/IP network via a serial-to-Ethernet converter. The plant's security team wants to reduce the risk of an attacker reaching the RTU from the corporate network. Which control is most effective?
Select an answer first - 39
What is the typical first stage in the attack lifecycle on an ICS/SCADA system?
Select an answer first - 40
A natural gas pipeline company allows third-party vendors to remotely access the DCS for maintenance via a shared VPN account. The vendor laptops are not managed by the company. Which attack vector is most directly introduced by this practice?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.