Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 2

ICS/SCADA Vulnerabilities ICSSCADA Practice Questions (Page 4)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
4concepts

Questions 16–20

  1. 16application · medium

    A municipal water utility uses a radio-based SCADA system for remote well sites. The protocol is unencrypted and lacks authentication. An attacker could potentially inject false telemetry or control commands. Which mitigation is most appropriate given the constraint that the radio infrastructure cannot be replaced?

    Select an answer first
  2. 17expert · hard

    A hospital's HVAC control system has two vulnerabilities: (1) a remote code execution in the building management system (BMS) server, and (2) a denial-of-service vulnerability in the chiller plant controller that could cause the chiller to shut down. The hospital has a backup chiller that can be manually started. Which vulnerability should be prioritized?

    Select an answer first
  3. 18application · medium

    A security consultant reviews a SCADA network and finds that the engineering workstation has a shared administrator account with a default password. The workstation is also used for routine internet browsing by engineers. Which vulnerability is most directly exposed by this configuration?

    Select an answer first
  4. 19application · medium

    A water treatment facility uses Modbus TCP between a PLC and an HMI. A security assessment reveals that the PLC accepts writes from any host on the control network without authentication. The facility cannot schedule a shutdown for a firmware update for another three months. What is the most appropriate immediate mitigation?

    Select an answer first
  5. 20expert · hard

    A pharmaceutical plant uses a legacy serial protocol (Modbus RTU) between a PLC and a SCADA server. The protocol has no authentication, and a risk assessment shows that an attacker with access to the serial link could alter setpoints. The plant cannot replace the PLC or the SCADA server. Which mitigation provides the best security improvement while maintaining operational reliability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.