
EC-CouncilICS/SCADA Cybersecurity
Domain 4Objective 3
Interpreting Advisory Notices and CVE ICSSCADA Practice Questions (Page 3)
Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
6concepts
Questions 11–15
- 11
A security analyst is investigating a potential vulnerability in a water treatment plant's SCADA system. The analyst finds a vendor advisory that mentions 'CVE-2022-1234' but does not provide a direct link to the CVE record. The analyst needs to confirm the vulnerability details. What is the most reliable way to obtain the CVE record?
Select an answer first - 12
A vendor advisory for a gas pipeline SCADA system includes the following sections: 'Affected Products', 'Severity', 'Remediation', and 'References'. The 'References' section lists several CVE IDs. A technician wants to quickly find the CVE that corresponds to the most critical vulnerability described in the advisory. What is the best approach?
Select an answer first - 13
In a CVE record, which field provides a narrative explanation of the vulnerability's technical nature and potential impact?
Select an answer first - 14
A CVE record for a PLC programming software includes the following description: 'The software does not enforce integrity checks on project files, allowing an attacker with local access to modify a project file and cause the PLC to execute unintended logic.' The affected configurations list 'Version 3.0 and earlier'. The CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H. A plant uses version 2.5 of the software. The vendor has released version 3.1, which the advisory states fixes the issue. The plant's engineers often share project files via email. What is the most important consideration for the plant?
Select an answer first - 15
Which field in a CVE record would you examine to determine the specific software versions that are vulnerable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.