
EC-CouncilICS/SCADA Cybersecurity
Domain 3Objective 4
Identify Vulnerabilities and Exploitation ICSSCADA Practice Questions (Page 1)
Part of the Introduction to Hacking ICS/SCADA domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 1–5
- 1
A cyber attack on a railway signaling system exploits a vulnerability in the interlocking system, allowing the attacker to send false track occupancy signals. The safety system is independent, but the interlocking system is now showing conflicting information. What is the most critical impact to assess?
Select an answer first - 2
Which of the following is a common vulnerability found in legacy ICS/SCADA hardware components?
Select an answer first - 3
A security consultant is assessing a food and beverage manufacturing facility. The facility uses a mix of modern and legacy PLCs, and the network is flat. The consultant identifies the following vulnerabilities: default credentials on the HMI, unencrypted Ethernet/IP traffic, a known buffer overflow in a legacy PLC, and lack of network segmentation. The facility cannot replace the legacy PLCs immediately. Which of the following mitigations should the consultant recommend? (Select all that apply.)
Select an answer first - 4
A factory's OT network has a mix of devices from multiple vendors, some of which are no longer supported. The factory is planning to implement a vulnerability management program. What is the most important first step in this program?
Select an answer first - 5
A utility company is planning to implement a security monitoring solution for its OT network. The network consists of several substations connected via a WAN. The company has a limited budget and must choose between deploying an IDS at each substation or deploying a centralized SIEM that collects logs from all devices. The company's primary concern is detecting attacks that exploit protocol vulnerabilities in real-time. Which solution is more appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.