Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 3

Interpreting Advisory Notices and CVE ICSSCADA Practice Questions (Page 5)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
6concepts

Questions 21–25

  1. 21foundation · easy

    Which section of an ICS/SCADA advisory notice typically includes the vendor-specific product names and version numbers that are affected by the vulnerability?

    Select an answer first
  2. 22foundation · easy

    When an ICS/SCADA security advisory is published, which of the following is a standard section that provides the specific actions the user should take to address the vulnerability?

    Select an answer first
  3. 23application · medium

    A security analyst is compiling a vulnerability report for a client's ICS environment. The analyst finds two references to the same vulnerability: one in a vendor advisory and one in a CVE record. The advisory uses 'CVE-2021-5555' and the CVE record uses 'CVE-2021-5555'. The analyst wants to ensure they are the same vulnerability. What should the analyst do?

    Select an answer first
  4. 24expert · hard

    A security analyst is investigating a potential vulnerability in a substation automation system. The analyst finds a CVE record that describes a vulnerability in a specific protocol implementation. The CVE record's references include a vendor advisory that lists a different CVE ID for the same issue. What should the analyst do?

    Select an answer first
  5. 25expert · hard

    A security engineer is evaluating two vulnerabilities in a chemical plant's distributed control system (DCS). CVE-2024-2001 has a CVSS base score of 9.8 with a vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. CVE-2024-2002 has a base score of 6.5 with a vector AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N. The plant's DCS is isolated from the internet but accessible from the corporate network via a firewall that allows only specific IPs. The engineer can only apply one mitigation this month. Which vulnerability should be prioritized?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.