Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 5Objective 2

NERC CIP ICSSCADA Practice Questions (Page 5)

Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 21–25

  1. 21application · medium

    A control system engineer is being hired to work at a utility. The role requires unescorted physical access to a control center that houses Critical Cyber Assets. The engineer has a clean criminal record and has passed a basic background check. According to NERC CIP, what additional step is required before the engineer can be granted this access?

    Select an answer first
  2. 22application · medium

    A utility is implementing NERC CIP's systems security management requirements. The security team is configuring malware protection on a Critical Cyber Asset. The asset is a legacy system that does not support the latest antivirus software. The team is considering using a host-based intrusion detection system (HIDS) as an alternative. What is the most appropriate action?

    Select an answer first
  3. 23expert · hard

    A utility has a recovery plan for its Critical Cyber Assets (CCAs) that includes a full restoration of all systems. During a test, the team discovers that the backup data is corrupted and cannot be restored. The compliance team wants to ensure the plan is effective. What is the most appropriate action?

    Select an answer first
  4. 24expert · hard

    A BES entity has a contractor who needs access to Critical Cyber Assets (CCAs) for a short-term project. The contractor has a valid background check from another utility. The entity wants to comply with CIP-004 without duplicating the background check. What is the most appropriate action?

    Select an answer first
  5. 25application · medium

    A utility is revising its cyber security policies to align with NERC CIP. The current policy document is a single, comprehensive document that covers all aspects of cyber security. The compliance team is concerned that this approach makes it difficult to update specific controls without affecting the entire policy. What is the most effective way to structure the policies to meet NERC CIP requirements and improve maintainability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.