Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 3Objective 4

Identify Vulnerabilities and Exploitation ICSSCADA Practice Questions (Page 4)

Part of the Introduction to Hacking ICS/SCADA domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 16–20

  1. 16application · medium

    A food processing plant uses a mix of modern and legacy PLCs. The legacy PLCs are critical to the production line but cannot be patched. Which strategy best mitigates the risk of exploitation while maintaining production?

    Select an answer first
  2. 17application · medium

    A vulnerability scan of a wastewater treatment plant identifies that the SCADA system uses default credentials on the HMI and that the network uses unencrypted Modbus TCP. Which vulnerability is the most critical to address first?

    Select an answer first
  3. 18expert · hard

    A regional water utility has a SCADA system with a mix of modern and legacy devices. The utility is under regulatory pressure to improve cybersecurity but has a limited budget. A recent risk assessment identified the following vulnerabilities: (1) default credentials on the HMI, (2) unencrypted Modbus TCP traffic, (3) a known buffer overflow in the legacy PLC firmware, and (4) lack of network segmentation between IT and OT. The utility cannot replace the legacy PLCs this year. Which combination of mitigations should the utility prioritize to achieve the most significant risk reduction?

    Select an answer first
  4. 19foundation · easy

    Which mitigation strategy is most effective in preventing command injection attacks in ICS/SCADA applications?

    Select an answer first
  5. 20application · medium

    A food and beverage plant has a mix of modern and legacy PLCs. The legacy PLCs use a proprietary serial protocol that is not encrypted. The plant is planning to connect the OT network to the corporate network for better visibility. What is the most important security control to implement before making this connection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.