Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 3

Interpreting Advisory Notices and CVE ICSSCADA Practice Questions (Page 1)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
6concepts

Questions 1–5

  1. 1application · medium

    A vendor advisory for a distributed control system (DCS) lists multiple CVEs, including CVE-2024-1111 and CVE-2024-1112. The advisory states that CVE-2024-1111 is resolved by patch A, and CVE-2024-1112 is resolved by patch B. The system administrator has only enough downtime to apply one patch this week. What should the administrator do?

    Select an answer first
  2. 2application · medium

    A CVE record for a human-machine interface (HMI) application includes the following description: 'The application does not properly validate input in the tag name field, allowing a remote authenticated user to inject commands.' The references include a vendor security bulletin and a patch link. An engineer wants to know if the vulnerability can be exploited by an unauthenticated attacker. What should the engineer do?

    Select an answer first
  3. 3expert · hard

    A manufacturing plant has a legacy SCADA system that is no longer supported by the vendor. A new advisory is published for a similar product line, and the plant's system is not listed in the affected products. However, the plant's system uses the same vulnerable component. The plant cannot upgrade due to cost. What should the plant do?

    Select an answer first
  4. 4foundation · easy

    In a CVSS vector string, which metric group reflects the characteristics of the vulnerability that are constant over time and across user environments?

    Select an answer first
  5. 5foundation · easy

    What is the primary role of a CVE identifier in vulnerability management for ICS/SCADA systems?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.