
EC-CouncilICS/SCADA Cybersecurity
Domain 5Objective 2
NERC CIP ICSSCADA Practice Questions (Page 6)
Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 26–30
- 26
A security analyst at a utility detects unusual outbound traffic from a device in the control network that is identified as a Critical Cyber Asset. The traffic pattern does not match any known application. The analyst suspects a potential compromise. According to NERC CIP, what is the first required action?
Select an answer first - 27
A utility is updating its cyber security policies to align with NERC CIP. The current policy for access control is outdated and does not reflect the current network architecture. The compliance team is responsible for updating the policy. What is the most important step in this process?
Select an answer first - 28
A regional entity conducts an audit of a BES entity and finds that the entity failed to implement a required cyber security policy under CIP-004. The entity had documented the policy but had not trained its staff on it. What is the most likely outcome?
Select an answer first - 29
What is the purpose of physical security controls under NERC CIP?
Select an answer first - 30
A system administrator is responsible for a set of Critical Cyber Assets (CCAs) that run a legacy operating system. The vendor no longer provides patches for this OS. The administrator wants to remain compliant with CIP-007. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.