Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 2Objective 6

ICS/SCADA Protocols ICSSCADA Practice Questions (Page 8)

Part of the TCP/IP and ICS/SCADA Protocols domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
5concepts

Questions 36–40

  1. 36foundation · easy

    Which of the following anomalies in ICS/SCADA protocol traffic should raise a security concern?

    Select an answer first
  2. 37foundation · easy

    Which protocol is specifically designed for electric utility SCADA systems and supports robust data transfer, event reporting, and peer-to-peer communication?

    Select an answer first
  3. 38expert · hard

    An analyst is reviewing a pcap from a DNP3 network and sees a master sending a 'Delay Measurement' request to an outstation. The outstation responds with a 'Delay Measurement' response, but the response contains an unexpected 'IIN' bit indicating 'Function Code Not Supported'. The analyst also notices that the master is sending the request repeatedly every 100 ms. What is the most likely cause?

    Select an answer first
  4. 39expert · hard

    An analyst is examining a pcap from a mixed network that includes both Modbus TCP and DNP3 traffic. The analyst notices that the Modbus TCP traffic shows a normal polling pattern, but the DNP3 traffic shows an unusually high rate of unsolicited responses from a single outstation. The analyst also sees that the DNP3 master is sending 'Disable Unsolicited' messages to that outstation, but the outstation continues to send unsolicited responses. What is the most likely cause?

    Select an answer first
  5. 40expert · hard

    A manufacturing company is integrating its OT network with the corporate IT network to allow real-time production monitoring. The OT network uses a mix of Modbus TCP and DNP3, while the IT network uses standard IT protocols. The security team is concerned about the inherent vulnerabilities of ICS protocols. What is the most effective way to mitigate the risk of unauthorized access to the OT network while still allowing the required data flow?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.