Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 4

Life Cycle of a Vulnerability and Exploit ICSSCADA Practice Questions (Page 3)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
5concepts

Questions 11–15

  1. 11expert · hard

    A vulnerability in a building management system (BMS) was discovered by a researcher and disclosed to the vendor. The vendor has not yet released a patch. Meanwhile, a security researcher publishes a detailed analysis of the vulnerability, including a proof-of-concept exploit. The facility manager must decide how to respond. Which response best addresses the risk?

    Select an answer first
  2. 12application · medium

    A water treatment facility runs a legacy HMI on a Windows 7 workstation that cannot be patched because the vendor no longer supports the OS. During a routine vulnerability scan, a critical remote code execution flaw is discovered in the HMI software. The facility's risk manager wants to reduce the likelihood of exploitation while a permanent fix is developed. Which action best aligns with the vulnerability life cycle stage between discovery and patch deployment?

    Select an answer first
  3. 13expert · hard

    An ICS security manager must decide how to handle a critical vulnerability in a legacy SCADA server that is still in production. The vendor has released a patch, but applying it requires a full system restart that will interrupt a continuous chemical process. The process cannot be stopped for at least two weeks. The manager has the following options. Which option best balances security and operational continuity?

    Select an answer first
  4. 14application · medium

    A utility company has a vulnerability in a transformer monitoring system. The vendor has released a patch, but the patch requires a reboot that will cause a brief outage. The company decides to wait until the next scheduled maintenance window. What is the primary risk of this decision?

    Select an answer first
  5. 15application · easy

    An ICS environment has a vulnerability in a human-machine interface (HMI) that was discovered by a vendor during internal testing. The vendor has not yet disclosed the vulnerability publicly. What stage of the vulnerability life cycle is this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.