
EC-CouncilICS/SCADA Cybersecurity
Domain 4Objective 3
Interpreting Advisory Notices and CVE ICSSCADA Practice Questions (Page 7)
Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
6concepts
Questions 31–35
- 31
A plant engineer receives an advisory for a programmable logic controller (PLC) that is used in a critical process. The advisory's 'Affected Products' section lists a specific model and firmware version. The engineer's PLC has a different firmware version. What should the engineer do?
Select an answer first - 32
A vulnerability researcher is analyzing CVE-2023-4567 and reads the description: 'A stack-based buffer overflow in the parsing of malformed packets may allow an unauthenticated remote attacker to execute arbitrary code.' The references section includes a link to a vendor advisory and a proof-of-concept exploit. What does this information tell the researcher?
Select an answer first - 33
In the CVE identifier CVE-2023-12345, what does the '2023' portion represent?
Select an answer first - 34
When an advisory provides a mitigation that involves restricting network access to the affected ICS device, what is the primary goal of this mitigation?
Select an answer first - 35
A municipal water treatment plant uses a SCADA system that is air-gapped from the corporate network. A new advisory is released for the SCADA software with a CVSS score of 8.1. The advisory recommends a patch that requires a full system restart. The plant can only restart the system during a scheduled shutdown next month. What should the team do in the meantime?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.