
EC-CouncilICS/SCADA Cybersecurity
Domain 4Objective 2
ICS/SCADA Vulnerabilities ICSSCADA Practice Questions (Page 7)
Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
4concepts
Questions 31–35
- 31
A chemical plant has a vulnerability in the safety instrumented system (SIS) that could allow an attacker to disable safety interlocks, and another vulnerability in the process control system (PCS) that could allow an attacker to alter setpoints. The plant is currently running at reduced capacity due to maintenance. Which vulnerability should be prioritized?
Select an answer first - 32
A pharmaceutical plant uses a DCS with proprietary protocols and legacy Windows-based HMIs that cannot be patched because the vendor has not validated updates. The plant runs 24/7 and production stoppages are extremely costly. Which mitigation strategy best balances security and operational continuity?
Select an answer first - 33
A wastewater treatment plant uses a serial connection between a PLC and a radio modem for remote monitoring. The radio link is unencrypted, and an attacker could intercept and modify messages. The plant cannot afford to replace the radio system. Which mitigation is most appropriate?
Select an answer first - 34
A power distribution company has a limited budget for security improvements. Two vulnerabilities are identified: (1) a remotely exploitable buffer overflow in the substation RTU that could cause a reboot, and (2) a lack of encryption on the communication link between the control center and the substation, which could allow eavesdropping on operational data. The RTU reboot would cause a temporary loss of monitoring but not a loss of control. Which mitigation should be funded first?
Select an answer first - 35
Which mitigation strategy is most appropriate for an ICS/SCADA system that cannot be patched immediately due to operational constraints?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.