
EC-CouncilICS/SCADA Cybersecurity
Domain 5Objective 6
NIST SP 800-82 ICSSCADA Practice Questions (Page 3)
Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
9concepts
Questions 11–15
- 11
A water treatment facility uses a flat network where the SCADA HMI, PLCs, and the corporate IT network all share the same broadcast domain. The facility manager wants to reduce the risk of a malware outbreak on the corporate network reaching the control system. According to NIST SP 800-82, which approach should be implemented first?
Select an answer first - 12
Which of the following is a methodology recommended in NIST SP 800-82 for assessing the security of an ICS?
Select an answer first - 13
An external auditor is conducting a security assessment of a chemical plant's DCS. The plant has a mature security program, but the auditor finds that the DCS does not have a formal patch management process. The operations team argues that patching is too risky because it could disrupt production. The auditor must recommend a course of action that aligns with NIST SP 800-82. Which recommendation is most appropriate?
Select an answer first - 14
In NIST SP 800-82, which category of security controls includes measures like physical security and personnel security?
Select an answer first - 15
Which of the following is a common vulnerability specific to ICS environments as identified in NIST SP 800-82?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.