
EC-CouncilICS/SCADA Cybersecurity
Domain 5Objective 2
NERC CIP ICSSCADA Practice Questions (Page 2)
Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 6–10
- 6
A BES entity has a Critical Cyber Asset (CCA) that runs a proprietary operating system. The vendor provides patches, but the entity is concerned that applying patches may disrupt grid operations. The entity wants to comply with CIP-007 while minimizing operational risk. What is the most appropriate approach?
Select an answer first - 7
What is the required frequency for testing recovery plans under NERC CIP?
Select an answer first - 8
A BES entity is considering whether to outsource the monitoring of its Critical Cyber Assets (CCAs) to a third-party vendor. The vendor will have remote access to the CCAs. The entity wants to ensure compliance with NERC CIP. Which consideration is most important?
Select an answer first - 9
A small generation facility that is part of the bulk electric system is evaluating its compliance obligations. The facility has a single turbine and a control system that is not connected to any external network. The facility's owner is unsure if NERC CIP applies. What is the primary factor that determines whether this facility must comply with NERC CIP?
Select an answer first - 10
A reliability coordinator is updating its Critical Cyber Asset (CCA) identification process for a 500 kV substation. The substation has a protective relay that communicates with a remote engineering workstation via a routable protocol. The relay also has a local serial port used only for maintenance. During the assessment, the team determines the relay is essential to the reliable operation of the Bulk Electric System (BES). Which asset should be registered as a Critical Cyber Asset?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.