Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 4

Life Cycle of a Vulnerability and Exploit ICSSCADA Practice Questions (Page 1)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
5concepts

Questions 1–5

  1. 1foundation · easy

    Which stage of the vulnerability life cycle involves creating and testing a fix for the identified flaw?

    Select an answer first
  2. 2expert · hard

    A vulnerability in a distributed control system (DCS) was discovered by a security researcher and disclosed to the vendor. The vendor has not yet released a patch, but the researcher has published a detailed analysis of the vulnerability. The DCS is used in a nuclear power plant, and the plant's safety regulations require that any known vulnerability be mitigated within 48 hours. What is the most appropriate action?

    Select an answer first
  3. 3foundation · easy

    In the exploit life cycle, what is the stage where an attacker creates a working method to take advantage of a vulnerability?

    Select an answer first
  4. 4application · medium

    A security analyst at a power plant notices that a newly discovered vulnerability in a PLC firmware has a proof-of-concept (PoC) exploit published on a public forum. The vendor has released a patch, but the patch has not been tested in the plant's environment. What should the analyst do first to minimize the risk of an exploit being used against the plant?

    Select an answer first
  5. 5expert · hard

    A vulnerability in a pipeline control system was discovered by an internal security team. The team has confirmed the vulnerability and is preparing to disclose it to the vendor. However, the team also found that the vulnerability is already being exploited in the wild. What is the most appropriate next step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.