Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 1Objective 5

Risk Assessment and Defining Types of Risk ICSSCADA Practice Questions (Page 4)

Part of the Introduction to ICS/SCADA Network Defense domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
7concepts

Questions 16–20

  1. 16application · medium

    During a risk assessment at a power utility, the team identified three risks: (1) a phishing email that could give an attacker access to the corporate network, (2) a misconfigured firewall that allows unauthorized external access to the SCADA DMZ, and (3) a potential physical intrusion into an unmanned substation. The team must prioritize these risks for treatment. Which risk should be treated first?

    Select an answer first
  2. 17expert · hard

    A power utility has identified a risk of a cyberattack on its grid control system. The cost to fully mitigate the risk is $2 million. The potential loss from a successful attack is estimated at $10 million, with a 10% annual likelihood. The utility is considering three options: (1) spend $2 million on mitigation, (2) purchase a cyber insurance policy for $500,000 per year, or (3) accept the risk. Which option is most financially justified?

    Select an answer first
  3. 18expert · hard

    A security team has completed a risk assessment and identified several risks. Management wants to track the status of each risk, including the likelihood, impact, treatment decision, and the person responsible for implementing the treatment. Which approach best supports this requirement?

    Select an answer first
  4. 19expert · hard

    A chemical plant has two risks to evaluate: Risk A has a likelihood of 3 and an impact of 4 (score 12), but the impact includes a potential fatality. Risk B has a likelihood of 5 and an impact of 3 (score 15), but the impact is only financial. The plant's risk matrix uses a simple product for scoring, but the safety department argues that Risk A should be prioritized because of the potential loss of life. How should the risk evaluation be handled?

    Select an answer first
  5. 20foundation · easy

    When an organization decides to purchase cyber insurance to cover potential losses from a cyber incident, which risk treatment option are they using?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.