Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 3

Interpreting Advisory Notices and CVE ICSSCADA Practice Questions (Page 4)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
6concepts

Questions 16–20

  1. 16application · medium

    A pharmaceutical manufacturer uses a legacy SCADA system that is no longer supported by the vendor. A new advisory is published for a vulnerability in the system with a CVSS score of 9.0, but no patch is available. The advisory suggests isolating the system from the corporate network as a mitigation. The plant's network team says full isolation would prevent required remote monitoring. What should the company do?

    Select an answer first
  2. 17application · medium

    A security engineer is reviewing CVE-2022-1234, which describes a buffer overflow in a specific model of a remote terminal unit (RTU). The CVE record's 'affected configurations' field lists firmware versions 1.0 through 1.5. The engineer's RTU runs firmware 1.6. What should the engineer conclude?

    Select an answer first
  3. 18foundation · easy

    Which CVSS metric group allows an organization to adjust the base score to reflect the importance of the affected asset to their specific environment?

    Select an answer first
  4. 19application · easy

    A security analyst is documenting a vulnerability found in a building management system. The analyst wants to reference the vulnerability in a report and link to the official CVE record. What should the analyst use?

    Select an answer first
  5. 20expert · hard

    A municipal water utility receives an advisory for a vulnerability in its SCADA historian with a CVSS base score of 8.1. The advisory provides a patch, but the patch requires a reboot of the historian, which would interrupt data collection for 15 minutes. The utility has a strict service-level agreement (SLA) that requires 99.9% uptime for the historian. The utility's maintenance window is scheduled for next month. The vulnerability is actively being exploited in the wild. What should the utility do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.