
EC-CouncilICS/SCADA Cybersecurity
Domain 5Objective 1
ISO 27001 ICSSCADA Practice Questions (Page 3)
Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
Questions 11–15
- 11
Which of the following is a specific security consideration when applying ISO/IEC 27001 to ICS/SCADA systems?
Select an answer first - 12
A nuclear power plant is implementing ISO 27001 and has identified that its control room workstations are connected to the corporate network for monitoring purposes. The security team is reviewing Annex A controls and must address the risk of malware being introduced from the corporate network. The plant has strict regulatory requirements that limit the use of encryption and require that all changes be approved by a safety committee. Which Annex A control is most appropriate to address this risk?
Select an answer first - 13
A transportation company is implementing ISO 27001 for its railway signaling system. The risk assessment identified that the signaling system uses a legacy protocol that is vulnerable to spoofing. The team is considering two treatment options: (1) upgrade the protocol, which is expensive and requires a full system outage, or (2) implement network monitoring to detect spoofing attempts. The company has a limited budget and cannot afford both. What is the most appropriate decision according to ISO 27001?
Select an answer first - 14
A chemical plant is integrating its OT environment into an ISO 27001-compliant ISMS. The team is mapping Annex A controls to the ICS environment. Which control implementation is MOST appropriate for the unique characteristics of the OT network?
Select an answer first - 15
A food processing company is implementing an ISMS and has defined its scope, policy, and risk assessment process. The team is now working on the Statement of Applicability (SoA). What is the PRIMARY purpose of the SoA?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.