Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 1Objective 5

Risk Assessment and Defining Types of Risk ICSSCADA Practice Questions (Page 7)

Part of the Introduction to ICS/SCADA Network Defense domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
7concepts

Questions 31–35

  1. 31expert · hard

    A risk manager at a nuclear power plant is evaluating two risks: Risk X has a low likelihood but a very high impact (potential core damage), while Risk Y has a high likelihood but a low impact (minor equipment failure). The plant has a very low risk tolerance due to regulatory requirements. How should the risk manager prioritize these risks?

    Select an answer first
  2. 32expert · hard

    A security consultant is hired to perform a risk assessment for a hospital's ICS environment, which includes HVAC, lighting, and medical gas monitoring systems. The hospital has a limited budget and wants to focus on risks that could affect patient safety. Which approach should the consultant take?

    Select an answer first
  3. 33application · medium

    A small water utility has identified that its SCADA system is vulnerable to a cyberattack that could disrupt water treatment. The utility cannot afford to upgrade the system, and management decides to accept the risk because the likelihood of an attack is low and the impact, while serious, is not life-threatening. Which risk treatment option has been applied?

    Select an answer first
  4. 34expert · hard

    A petrochemical facility has a legacy DCS that controls a critical distillation column. The DCS has known vulnerabilities, but replacing it would cost $10 million and take two years. The facility is required to maintain production to meet contractual obligations. The risk team has identified that a cyberattack could cause a catastrophic release, but the likelihood is low because the DCS is isolated from the internet. Management is considering whether to accept the risk or implement compensating controls. What is the most appropriate decision?

    Select an answer first
  5. 35foundation · easy

    Which of the following is a risk specific to ICS/SCADA environments that is less common in traditional IT systems?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.