
EC-CouncilICS/SCADA Cybersecurity
Domain 4Objective 2
ICS/SCADA Vulnerabilities ICSSCADA Practice Questions (Page 6)
Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
4concepts
Questions 26–30
- 26
A manufacturing plant uses DNP3 for communication between a master station and remote terminal units (RTUs). A security assessment finds that DNP3 traffic is unencrypted and can be spoofed. The plant cannot replace the RTUs or the master station in the near term. Which mitigation strategy is most appropriate?
Select an answer first - 27
A natural gas pipeline operator uses a wireless mesh network to connect remote pressure sensors to a central control system. The wireless protocol is known to be susceptible to replay attacks. An attacker could replay a 'normal pressure' reading to mask an actual overpressure condition. What is the most significant consequence of this vulnerability?
Select an answer first - 28
A water treatment facility uses legacy PLCs that communicate over Modbus TCP. The ICS network is flat and the PLCs have no authentication. Management wants to reduce the risk of unauthorized writes to the PLCs without replacing them. Which mitigation should the team implement first?
Select an answer first - 29
A refinery has two vulnerabilities: (1) a buffer overflow in the HMI software that can be triggered remotely and causes the HMI to crash, and (2) a misconfigured firewall that allows external access to the historian database, which contains non-critical process data. The HMI is used for monitoring but not for safety-critical control. The historian is not directly connected to the control network. Which vulnerability should be prioritized?
Select an answer first - 30
A cyber incident at a chemical plant involves an attacker exploiting a vulnerability in the OPC UA server to read and modify process setpoints. The plant's safety systems are independent and not affected. What is the most significant impact of this incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.