Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 1Objective 5

Risk Assessment and Defining Types of Risk ICSSCADA Practice Questions (Page 9)

Part of the Introduction to ICS/SCADA Network Defense domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
7concepts

Questions 41–43

  1. 41application · medium

    A water utility's SCADA system uses legacy Windows XP HMIs and unencrypted Modbus TCP between the control center and remote pumping stations. During a risk assessment, the team identifies that a successful exploit of the HMI could allow an attacker to alter pump setpoints, and that the Modbus traffic could be intercepted. Which type of risk does the unencrypted Modbus communication primarily represent?

    Select an answer first
  2. 42foundation · easy

    A risk that arises from inadequate procedures or human errors in the control room is best classified as which type of risk?

    Select an answer first
  3. 43application · medium

    A chemical plant has a legacy PLC that controls a critical reactor. The risk team has determined that a successful cyberattack on the PLC could cause a toxic release, but the likelihood of such an attack is very low because the PLC is not connected to any external network. According to risk analysis principles, how should this risk be characterized?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to ICSSCADA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.