
EC-CouncilICS/SCADA Cybersecurity
Domain 3Objective 4
Identify Vulnerabilities and Exploitation ICSSCADA Practice Questions (Page 7)
Part of the Introduction to Hacking ICS/SCADA domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 31–35
- 31
A power plant's turbine control system is connected to a corporate network for remote monitoring. An attacker has compromised a corporate server and is now attempting to pivot to the turbine control system. The control system uses a proprietary protocol that is not encrypted. What is the most significant risk to the turbine's physical operation?
Select an answer first - 32
A chemical plant has a distributed control system (DCS) where the safety instrumented system (SIS) is separate from the basic process control system (BPCS). An attacker has exploited a vulnerability in the BPCS's OPC server, gaining the ability to write to process tags. The SIS is not directly connected to the corporate network and is considered isolated. What is the most significant risk to the plant's safety?
Select an answer first - 33
A pharmaceutical manufacturing plant has a batch reactor where an attacker has exploited a vulnerability in the historian data collection service. The attacker is able to modify the temperature readings sent to the batch control system, causing it to believe the reactor is cooler than it actually is. What is the most significant potential impact of this manipulation?
Select an answer first - 34
A security assessment of a power utility's SCADA system reveals that the HMI software is running with administrative privileges and has a known buffer overflow vulnerability. What is the most likely consequence if an attacker exploits this vulnerability?
Select an answer first - 35
Which of the following is a potential impact of exploiting a vulnerability in an ICS/SCADA system that controls a power grid?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.