Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 6

Prioritizing Vulnerabilities with CVSS and OVAL ICSSCADA Practice Questions (Page 4)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
10concepts

Questions 16–20

  1. 16application · medium

    A vulnerability in a remote terminal unit (RTU) has a CVSS base score of 7.5. The vendor has released a patch, but it has not been widely tested in the ICS environment. There is no public exploit code. The security team is deciding whether to prioritize this vulnerability. What is the most appropriate next step?

    Select an answer first
  2. 17expert · hard

    An analyst is calculating the environmental score for a vulnerability affecting a safety instrumented system (SIS) controller. The base score is 8.0. The organization has determined that the confidentiality requirement is low (CR:L), the integrity requirement is high (IR:H), and the availability requirement is high (AR:H). The vulnerability is only exploitable from the local network (MAV:A). Which statement best describes the effect of these environmental metrics on the final score?

    Select an answer first
  3. 18application · medium

    A water treatment facility uses a vulnerability scanner that reports a CVSS v3.1 base score of 9.8 for a remote code execution flaw in a human-machine interface (HMI) server. The HMI is isolated on a flat OT network with no internet connectivity, requires local authentication, and is scheduled for replacement in 60 days. The security team has limited patching windows and must prioritize this week's maintenance. What should the team do with this finding?

    Select an answer first
  4. 19foundation · easy

    In an ICS/SCADA environment, why is it beneficial to use OVAL results alongside CVSS scores when deciding which vulnerabilities to remediate first?

    Select an answer first
  5. 20foundation · easy

    What is the purpose of an OVAL 'state' in a vulnerability assessment test?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.