
EC-CouncilICS/SCADA Cybersecurity
Domain 3Objective 4
Identify Vulnerabilities and Exploitation ICSSCADA Practice Questions (Page 3)
Part of the Introduction to Hacking ICS/SCADA domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 11–15
- 11
A cyber incident at a natural gas pipeline company results in an attacker using a command injection vulnerability to alter the pressure setpoints in a compressor station. What is the most critical impact to assess?
Select an answer first - 12
A power utility has a SCADA system with legacy devices that cannot be patched. The utility is required to maintain high availability and cannot afford a full network redesign. A recent security assessment identified that the legacy devices are exposed to the corporate network. Which mitigation approach is most appropriate?
Select an answer first - 13
A penetration tester is assessing a natural gas pipeline's SCADA system. The tester discovers that the HMI application parses a vendor-specific binary file format without proper bounds checking. The tester crafts a malformed file that, when opened by an operator, causes the HMI process to crash and restart. What is the most likely exploitation technique being used, and what is the primary immediate impact?
Select an answer first - 14
Which of the following is a common software vulnerability in ICS/SCADA systems?
Select an answer first - 15
Which of the following is a common mitigation strategy to prevent exploitation of ICS/SCADA network vulnerabilities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.