
EC-CouncilICS/SCADA Cybersecurity
Domain 3Objective 4
Identify Vulnerabilities and Exploitation ICSSCADA Practice Questions (Page 2)
Part of the Introduction to Hacking ICS/SCADA domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 6–10
- 6
What is the most significant potential impact of exploiting a vulnerability in a safety-critical ICS/SCADA system?
Select an answer first - 7
A security analyst is investigating an incident at a manufacturing plant. The plant uses a legacy protocol that lacks authentication. The analyst finds that an attacker has been sending crafted packets to a PLC, causing it to cycle through different states rapidly. The PLC is connected to a robotic arm. What is the most likely attack technique and its primary impact?
Select an answer first - 8
A mining operation uses a SCADA system to control conveyor belts. The system has a known vulnerability in the OPC UA server that allows an unauthenticated attacker to read and write data. The plant manager is concerned about the potential impact. What is the most direct physical impact an attacker could have by exploiting this vulnerability?
Select an answer first - 9
A security engineer is testing the security of a SCADA system. The engineer sends a specially crafted packet to a PLC that is designed to overflow a buffer in the PLC's network stack, causing it to execute arbitrary code. What is the most likely immediate impact of this attack?
Select an answer first - 10
A regional electrical utility is planning to upgrade its substation automation. The current system uses legacy serial DNP3, which is unauthenticated. The utility has a limited budget and must choose between two projects: (1) upgrading all RTUs to support DNP3 Secure Authentication, or (2) deploying a next-generation firewall with DNP3 inspection at each substation's network boundary. The utility's risk assessment shows that the most likely attack vector is from the corporate network via a compromised engineering workstation. Which project should the utility prioritize?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.