Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 3

Interpreting Advisory Notices and CVE ICSSCADA Practice Questions (Page 6)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
6concepts

Questions 26–30

  1. 26application · easy

    A cybersecurity analyst is reviewing an advisory for a gas pipeline SCADA system. The advisory includes a 'Severity' section that states 'High' and a 'Remediation' section that says 'Upgrade to version 2.1.0 or later.' The analyst's system is running version 2.0.5. What should the analyst do?

    Select an answer first
  2. 27foundation · easy

    When correlating an advisory notice to CVE entries, what is the primary purpose of the CVE references listed in the advisory?

    Select an answer first
  3. 28application · medium

    A power distribution company receives an advisory for a vulnerability in their substation gateway. The advisory lists a firmware update, but the update requires a maintenance window that would interrupt power monitoring for 30 minutes. The advisory also lists a workaround that involves restricting network access to the gateway via firewall rules. The company cannot schedule the maintenance window for two weeks. What should the company do immediately?

    Select an answer first
  4. 29application · medium

    A water utility's engineering team receives a vendor advisory for their SCADA HMI software. The advisory lists affected product versions, a CVSS score of 9.8, and a 'Workaround' section that describes disabling a specific DCOM interface. The team needs to protect the system immediately while the vendor develops a patch. What should the team do first?

    Select an answer first
  5. 30expert · hard

    A vendor advisory for a remote access gateway used in an oil refinery lists two CVEs: CVE-2024-3001 and CVE-2024-3002. The advisory's remediation section states that firmware version 2.0 resolves CVE-2024-3001, but does not mention CVE-2024-3002. The refinery is running firmware 1.9. The CVE record for CVE-2024-3002 lists a patch in firmware 2.1. The refinery's change management policy requires that any firmware update be tested for at least two weeks before deployment. What should the refinery do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.