
EC-CouncilICS/SCADA Cybersecurity
Domain 1Objective 5
Risk Assessment and Defining Types of Risk ICSSCADA Practice Questions (Page 3)
Part of the Introduction to ICS/SCADA Network Defense domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 11–15
- 11
A pipeline operator is analyzing the risk of a cyberattack on its leak detection system. The team has two data sources: (1) threat intelligence shows that similar attacks have occurred in the industry, but (2) the company's own security monitoring has not detected any attempts. The team must decide how to rate the likelihood of this risk. What is the most appropriate approach?
Select an answer first - 12
A risk analyst is evaluating the risk of a ransomware attack on a hospital's building management system (BMS). The analyst estimates that the attack could shut down HVAC systems for 48 hours, affecting patient comfort but not life-safety systems. The likelihood of the attack is moderate because the BMS is on a separate network but has some internet exposure. How should the analyst characterize the risk?
Select an answer first - 13
A large utility is planning to integrate its OT network with a new cloud-based analytics platform. The security team is asked to perform a risk assessment before the integration. The team is divided: some want to do a full quantitative risk assessment, while others prefer a qualitative approach. The project timeline is tight, and the integration is scheduled to go live in three weeks. What is the most appropriate approach?
Select an answer first - 14
A small brewery's automation system uses a PLC that is no longer supported by the vendor. The risk assessment shows that a failure of the PLC would halt production for a week, costing $100,000. The brewery has a limited budget and decides that the cost of replacing the PLC ($150,000) is not justified. They decide to keep the PLC and accept the risk. What should the team document in the risk register?
Select an answer first - 15
A municipal water utility is conducting a risk identification workshop. The team lists the following potential risks: (1) a disgruntled former employee using still-valid VPN credentials, (2) a flood damaging the primary control room, (3) a ransomware attack on the billing system, and (4) a vendor's remote maintenance session being hijacked. Which of these is a threat specifically tied to the ICS/SCADA environment rather than a general IT risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.