
EC-CouncilICS/SCADA Cybersecurity
Domain 4Objective 6
Prioritizing Vulnerabilities with CVSS and OVAL ICSSCADA Practice Questions (Page 9)
Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 41–45
- 41
A security engineer is calculating the CVSS v3.1 base score for a vulnerability in a building management system (BMS) controller. The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L. The engineer needs to assign a qualitative severity rating. Which rating is correct for this base score?
Select an answer first - 42
A regional energy cooperative must submit vulnerability assessment reports to a federal regulator. The regulator requires that the reports be generated using a standardized, machine-readable format that can be validated and compared across all utilities. The cooperative currently uses a mix of custom scripts and vendor-specific reports. What should the cooperative adopt to meet the regulator's requirement?
Select an answer first - 43
What is the primary purpose of the Open Vulnerability and Assessment Language (OVAL)?
Select an answer first - 44
Which of the following metric groups are part of the CVSS v3.x scoring system?
Select an answer first - 45
A security analyst is presenting a vulnerability management report to plant management. The report lists several vulnerabilities with CVSS scores. The plant manager asks, 'Why do we have a critical score of 9.8 for a vulnerability on a printer, but a high score of 7.5 for a vulnerability on our main control server? Shouldn't the server be more important?' What is the best response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.