
EC-CouncilICS/SCADA Cybersecurity
Domain 6Objective 6
Mitigating the Risk of Legacy Machines ICSSCADA Practice Questions (Page 2)
Part of the Securing the ICS Network domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
7concepts
Questions 6–10
- 6
What is virtual patching?
Select an answer first - 7
A water utility has a legacy SCADA system that is segmented from the corporate network. The system has no host-based monitoring capabilities. The security team has deployed a network-based IDS (NIDS) on the SCADA segment. They want to detect a sophisticated attacker who is using encrypted communications to hide their activity. Which additional monitoring technique would be most effective?
Select an answer first - 8
A manufacturing plant runs a legacy SCADA server on Windows Server 2003 that has a known remote code execution vulnerability. The vendor no longer provides patches, and the server cannot be taken offline. The security team wants to mitigate the vulnerability without modifying the server's software. Which technique should they use?
Select an answer first - 9
An energy company has a legacy substation RTU that communicates with a central SCADA system over an IP network. The RTU runs an outdated firmware with known vulnerabilities. The company wants to isolate the RTU from the corporate network while still allowing the SCADA system to poll it. What is the most effective network segmentation approach?
Select an answer first - 10
A water treatment facility has a 15-year-old SCADA server running Windows NT 4.0 that controls the chlorine dosing process. The server cannot be patched or upgraded without a full plant shutdown, which is not approved until next year. The server must remain accessible to the engineering workstation subnet for HMI display and alarm acknowledgment. The ICS network is already isolated from the corporate network by a firewall. What is the MOST effective immediate control to reduce the risk of a remote attacker exploiting the unpatched server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.