Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 5Objective 1

ISO 27001 ICSSCADA Practice Questions (Page 4)

Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
6concepts

Questions 16–20

  1. 16foundation · easy

    What is the primary purpose of the ISO/IEC 27001 standard?

    Select an answer first
  2. 17expert · hard

    A large transportation authority has implemented an ISMS for its traffic control systems. During the Stage 2 certification audit, the auditor finds that the internal audit team did not audit the OT network segment due to safety concerns. The auditor issues a major non-conformity. What is the MOST appropriate corrective action?

    Select an answer first
  3. 18application · medium

    A manufacturing company is aligning its OT environment with ISO 27001. The security team is reviewing Annex A controls and needs to select controls that specifically address the risk of unauthorized changes to PLC program logic. Which combination of Annex A control categories is most directly relevant to this risk?

    Select an answer first
  4. 19application · medium

    A regional water utility is implementing ISO 27001 and has defined its ISMS scope to include the SCADA network that controls water treatment. During the risk assessment, the team identifies that a legacy PLC on the plant floor has no authentication mechanism and is directly accessible from the corporate IT network. According to ISO 27001 requirements, what must the utility do as part of the risk treatment process?

    Select an answer first
  5. 20expert · hard

    A manufacturing company is undergoing its ISO 27001 certification audit. During the audit, the auditor finds that the company's incident response plan for the OT environment has not been tested in the past two years. The company argues that testing the plan would require a production shutdown, which is not feasible. The auditor issues a major nonconformity. What is the most appropriate action for the company to take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.