Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 6

Prioritizing Vulnerabilities with CVSS and OVAL ICSSCADA Practice Questions (Page 6)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
10concepts

Questions 26–30

  1. 26application · medium

    A water treatment facility uses a CVSS base score of 9.8 to prioritize patching a vulnerability in its PLC programming workstation. The workstation is on an isolated network segment with no internet access, requires physical presence to exploit, and is not connected to any corporate systems. The security manager insists on patching this vulnerability before a separate 7.5-scored vulnerability that is remotely exploitable from the corporate network and affects the HMI server. Which approach best addresses the prioritization flaw?

    Select an answer first
  2. 27application · medium

    A vulnerability assessment of a remote terminal unit (RTU) management server identifies a flaw with the CVSS v3.1 vector CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N. The server is accessed only by two senior engineers via a jump host. The security manager asks whether this should be treated as a critical finding. What is the most accurate assessment of this vulnerability?

    Select an answer first
  3. 28foundation · easy

    Which of the following is a temporal metric in CVSS v3.x?

    Select an answer first
  4. 29application · medium

    A security analyst is prioritizing vulnerabilities in a power utility's OT environment. Two findings have identical CVSS v3.1 base scores of 8.1. Finding 1 has a public exploit available and a vendor-provided patch that has been deployed to 90% of assets. Finding 2 has no known exploit and only a temporary workaround. The analyst must decide which to remediate first. What is the most appropriate action?

    Select an answer first
  5. 30application · medium

    A patch management engineer is reviewing a vulnerability report for a programmable logic controller (PLC) programming workstation. The report lists the following CVSS v3.1 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The workstation is on a segmented OT network, and the engineer needs to explain the exposure to the operations manager. Which statement accurately describes what this vector indicates?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.