Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 6

Prioritizing Vulnerabilities with CVSS and OVAL ICSSCADA Practice Questions (Page 2)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
10concepts

Questions 6–10

  1. 6application · medium

    A patch management team is prioritizing vulnerabilities in a power utility's ICS environment. They have two vulnerabilities with the same base score of 8.8. Vulnerability A has a public exploit available and no vendor patch yet. Vulnerability B has no public exploit and a vendor patch released last week. The team can only patch one system this week. Which vulnerability should be prioritized?

    Select an answer first
  2. 7application · medium

    A cybersecurity consultant is tasked with evaluating the vulnerability assessment capabilities of a small water utility. The utility uses a single vendor's scanner and wants to ensure that its assessment results can be shared with a regional threat intelligence sharing group. The group requires that all members submit findings in a standardized format. What should the consultant recommend?

    Select an answer first
  3. 8application · medium

    A utility company uses two different vulnerability scanners: one from Vendor X for its Windows-based engineering workstations and one from Vendor Y for its Linux-based data historians. The security team wants to ensure both scanners produce consistent results for the same configuration checks. What is the most effective way to achieve this consistency?

    Select an answer first
  4. 9foundation · easy

    Why should an organization not rely solely on CVSS base scores when prioritizing vulnerabilities in an ICS/SCADA environment?

    Select an answer first
  5. 10application · medium

    An analyst is reviewing a vulnerability report for a gas pipeline SCADA system. The CVSS vector string is: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The analyst needs to explain to the operations manager why this vulnerability is rated critical even though the affected device is behind a firewall. Which statement accurately describes the base score's meaning?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.