
EC-CouncilICS/SCADA Cybersecurity
Domain 5Objective 4
ISA99 ICSSCADA Practice Questions (Page 3)
Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 11–15
- 11
A power plant is implementing ISA99 zones and conduits for its turbine control system. The system has a turbine controller that communicates with a remote monitoring center via a satellite link. The remote monitoring center is operated by a third party. The plant wants to ensure that the remote monitoring center cannot send commands to the turbine controller. What is the most appropriate way to implement this using the zones and conduits model?
Select an answer first - 12
A pharmaceutical company is implementing ISA99 foundational requirements for its new filling line. The system must ensure that only authorized operators can change recipe parameters, and that any changes are logged. Which combination of foundational requirements is most directly applicable?
Select an answer first - 13
A manufacturing plant is implementing ISA99 guidance for securing its industrial network. The plant has a legacy PLC that cannot be patched. The PLC is in a zone with other devices that have been patched. What is the most practical implementation guidance for the legacy PLC?
Select an answer first - 14
A pharmaceutical company is performing an ISA99 risk assessment for its batch processing system. The system has a vulnerability in the batch controller that could allow an attacker to alter the recipe. The company has a strict regulatory requirement to validate any changes to the system. The risk assessment team is considering two countermeasures: (A) apply a vendor patch that requires a system restart, or (B) implement an application whitelist that blocks unauthorized executables. Which countermeasure is more appropriate given the regulatory validation requirement?
Select an answer first - 15
A chemical plant is implementing ISA99 security levels for its process control system. The system has a target security level (SL-T) of SL 2. The current security level (SL-C) is assessed as SL 1 because the system lacks user authentication and has no audit logging. The plant has a limited budget and must choose between two projects: (A) implement user authentication, or (B) implement audit logging. Which project should the plant prioritize to achieve SL 2?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.