
EC-CouncilICS/SCADA Cybersecurity
Domain 5Objective 4
ISA99 ICSSCADA Practice Questions (Page 10)
Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 46–47
- 46
A refinery is conducting an ISA99 risk assessment for its crude unit. The crude unit has a DCS that is connected to a remote access server for vendor support. The remote access server is in a demilitarized zone (DMZ) and requires two-factor authentication. The risk assessment identifies that a successful attack on the DCS could cause a fire, but the likelihood is considered low because of the existing controls. The target security level (SL-T) for the crude unit zone is SL 2. The current security level (SL-C) is assessed as SL 1 because the DCS does not have application whitelisting. The team is considering two countermeasures: (A) implement application whitelisting on the DCS, or (B) remove the remote access server and require vendors to be on-site. Which countermeasure is most aligned with the ISA99 risk assessment methodology?
Select an answer first - 47
A water treatment plant is implementing ISA99 guidance. They have a limited budget and need to prioritize security improvements. The plant has a single control network with no segmentation, and remote access is provided via a VPN. Which improvement should be prioritized according to ISA99's risk-based approach?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ICSSCADA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.