Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 5Objective 2

NERC CIP ICSSCADA Practice Questions (Page 1)

Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 1–5

  1. 1application · medium

    A utility is developing its NERC CIP cyber security policy. The compliance team wants to ensure the policy is enforceable and auditable. They have drafted a policy that includes roles and responsibilities, but they have not yet defined how employees with access to Critical Cyber Assets (CCAs) will be vetted. Which addition is most directly required to align with CIP-004?

    Select an answer first
  2. 2foundation · easy

    How are NERC CIP standards organized internally?

    Select an answer first
  3. 3expert · hard

    A utility has experienced a cyber security incident that affected a Critical Cyber Asset. The incident was contained, and the utility has completed its internal investigation. The utility has determined that the incident was caused by a phishing email that led to the compromise of a workstation with access to the control network. The utility is now preparing its report to the relevant authorities. What is the most important element to include in the report?

    Select an answer first
  4. 4foundation · easy

    What is the purpose of a recovery plan under NERC CIP?

    Select an answer first
  5. 5expert · hard

    A utility is upgrading the physical security at a control center that houses Critical Cyber Assets. The current system uses a simple keypad for door access. The utility wants to implement a more robust system that provides an audit trail. The budget is limited, and the utility is considering two options: a proximity card system with a central logging system, or a biometric system with local logging. The control center is staffed 24/7, and the security team is concerned about the reliability of the logging system. What is the most important factor in choosing between these two systems?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.