Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 5Objective 6

NIST SP 800-82 ICSSCADA Practice Questions (Page 7)

Part of the Standards and Regulations for Cybersecurity domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
9concepts

Questions 31–35

  1. 31expert · hard

    A power plant has a legacy control system that cannot be patched because the vendor is out of business. The plant must remain operational. The security manager is considering several compensating controls. Which combination of controls provides the most robust defense-in-depth for this unpatched system, according to NIST SP 800-82?

    Select an answer first
  2. 32application · medium

    A manufacturing company is developing an ICS security program for the first time. The security manager has been asked to ensure that the program aligns with NIST SP 800-82. Which sequence of actions best follows the guidance in NIST SP 800-82?

    Select an answer first
  3. 33application · medium

    A water utility has implemented network segmentation and firewalls according to NIST SP 800-82. The security manager now wants to ensure that security monitoring is effective. Which practice is most aligned with SP 800-82's guidance for ICS operations?

    Select an answer first
  4. 34application · medium

    A cybersecurity analyst is evaluating the risk of a remote attacker exploiting a vulnerability in a PLC's web server. The PLC is on a segmented control network, but the analyst finds that the PLC's firmware is outdated and has known vulnerabilities. According to NIST SP 800-82, which combination of factors is most relevant to this risk?

    Select an answer first
  5. 35expert · hard

    A water utility has implemented an IDS on its SCADA network. The IDS generates a large number of false positives, causing the security team to ignore alerts. The operations team is concerned that the IDS is also introducing latency. The security manager needs to improve the effectiveness of the monitoring program. Which action is most aligned with NIST SP 800-82?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.