Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 5Objective 2

NERC CIP ICSSCADA Practice Questions (Page 9)

Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 41–45

  1. 41application · medium

    A control room operator at a BES facility is reviewing the physical security plan for a substation that contains Critical Cyber Assets (CCAs). The plan currently includes a fence, a locked gate, and a camera system. During a review, the operator notices that the camera footage is only retained for 48 hours. The compliance lead flags this as a potential gap. What is the most likely reason this is a compliance issue?

    Select an answer first
  2. 42application · medium

    A security analyst at a BES entity detects unusual outbound traffic from a Critical Cyber Asset (CCA) to an external IP address. The analyst suspects a possible compromise. According to CIP-008, what is the first required action?

    Select an answer first
  3. 43expert · hard

    A utility is performing its annual CCA identification. The team has identified a set of cyber assets that include a historian server, a firewall, and a remote access server. The historian server collects data from multiple substations. The firewall is the only gateway between the control network and the corporate network. The remote access server allows vendors to connect to the control network. The team is debating whether the firewall should be classified as a CCA. The firewall does not directly control any BES equipment, but it is the sole point of connectivity. What is the most defensible classification for the firewall?

    Select an answer first
  4. 44expert · hard

    A utility is implementing NERC CIP personnel and training requirements. The utility has a mix of employees and contractors who need access to Critical Cyber Assets. The contractors are from a third-party vendor and will have remote access to the control system for maintenance. The utility's current policy requires all personnel to undergo a personnel risk assessment, but the vendor has already performed a background check on its employees. The vendor is requesting that the utility accept their background check to avoid duplicating the process. What is the most appropriate action?

    Select an answer first
  5. 45expert · hard

    A utility is developing a recovery plan for its Critical Cyber Assets. The plan includes procedures for restoring the control system after a cyber attack. The utility has a limited budget and must decide whether to invest in a full-scale recovery test or a tabletop exercise. The compliance team is concerned about meeting NERC CIP's testing requirements. What is the most appropriate approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.