Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 4

Life Cycle of a Vulnerability and Exploit ICSSCADA Practice Questions (Page 7)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
5concepts

Questions 31–35

  1. 31foundation · easy

    In the vulnerability life cycle, which stage immediately follows the discovery of a vulnerability by a researcher or vendor?

    Select an answer first
  2. 32application · medium

    A water utility discovers a vulnerability in its SCADA HMI software during an internal penetration test. The vendor has not yet released a patch, and the exploit code is already publicly available. The utility cannot take the HMI offline because it controls critical pumps. Which action best reduces risk while the vulnerability is in the 'patch not available' stage of its life cycle?

    Select an answer first
  3. 33application · easy

    A security team is tracking a vulnerability in a SCADA system. The timeline shows: vulnerability discovered by researcher, disclosed to vendor, vendor releases patch, and then a public exploit is released. What is the correct order of these events?

    Select an answer first
  4. 34application · medium

    An ICS security team is building a timeline for a newly discovered vulnerability in a remote terminal unit (RTU). The vulnerability was found by a researcher, reported to the vendor, and a patch is expected in 60 days. The team wants to display the relationship between vulnerability disclosure and exploit availability. Which timeline correctly represents the typical progression?

    Select an answer first
  5. 35application · medium

    A security analyst is assessing the risk of a vulnerability in a water treatment plant's control system. The vulnerability has been disclosed, but no exploit is publicly available. The vendor has released a patch, but the plant has not yet applied it. What is the most accurate risk assessment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.