Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 5Objective 1

ISO 27001 ICSSCADA Practice Questions (Page 5)

Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
6concepts

Questions 21–25

  1. 21expert · hard

    A nuclear research facility is implementing ISO 27001. The risk assessment team has identified a risk of unauthorized physical access to the control room. The facility has a strict safety culture, and any changes to the control room layout are heavily regulated. The team is considering controls: (1) installing biometric access control, (2) adding a security guard, or (3) implementing a two-person rule. Which control is MOST appropriate given the regulatory constraints?

    Select an answer first
  2. 22application · medium

    A manufacturing company has implemented an ISMS for its ICS environment and is preparing for ISO 27001 certification. The internal audit has been completed, and the audit team identified several non-conformities. What is the mandatory NEXT step in the certification process?

    Select an answer first
  3. 23application · medium

    A small water utility wants to achieve ISO 27001 certification for its SCADA system. The management team is unsure about the scope of the ISMS. According to ISO 27001, what should the organization do to define the scope?

    Select an answer first
  4. 24expert · hard

    A petrochemical company is implementing ISO 27001 for its refinery control systems. The risk assessment identified that the safety instrumented system (SIS) has a critical vulnerability that could allow an attacker to disable safety shutdown functions. The SIS vendor has released a patch, but applying it requires a full plant shutdown, which would cost $2 million in lost production. The company's risk acceptance criteria state that risks with a potential impact on human safety cannot be accepted. What is the most appropriate risk treatment decision?

    Select an answer first
  5. 25foundation · easy

    In the ISO/IEC 27001 risk management process, what is the purpose of risk identification?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.