
EC-CouncilICS/SCADA Cybersecurity
Domain 4Objective 4
Life Cycle of a Vulnerability and Exploit ICSSCADA Practice Questions (Page 8)
Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 36–39
- 36
A security analyst is constructing a vulnerability life cycle timeline for a flaw in a natural gas compressor station's control system. The vulnerability was discovered by a vendor researcher, and the vendor has developed a patch but is holding it for a scheduled release in three months. Meanwhile, a third-party researcher has independently discovered the same vulnerability and plans to disclose it publicly next week. What is the best course of action for the vendor?
Select an answer first - 37
Which stage of the exploit life cycle involves the actual use of an exploit against a target system?
Select an answer first - 38
A manufacturing plant has a vulnerability in its industrial control system that is in the 'patch available' stage. However, the plant's change management process requires a two-week testing period before deployment. During this time, the plant is at increased risk. What should the security team do to reduce the risk during this period?
Select an answer first - 39
A vulnerability in a building management system (BMS) was disclosed publicly two weeks ago. The vendor has released a patch, but the facility manager has delayed deployment because of a scheduled production shutdown next month. Meanwhile, a proof-of-concept exploit has been published. What is the most appropriate risk management decision?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ICSSCADA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.