Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 1Objective 4

Risk Management in ICS/SCADA ICSSCADA Practice Questions (Page 7)

Part of the Introduction to ICS/SCADA Network Defense domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
7concepts

Questions 31–35

  1. 31application · medium · select all that apply

    A power generation facility has identified a high-risk vulnerability in its turbine control system. The risk assessment recommends reducing the risk to an acceptable level. Which of the following mitigation strategies are appropriate for this situation? Select all that apply.

    Select an answer first
  2. 32expert · hard

    A manufacturing company has identified a critical vulnerability in its industrial control system that could allow an attacker to stop production. The vulnerability is in a third-party component that is used in multiple production lines. The company has a risk tolerance that allows for a maximum downtime of 4 hours per incident. The estimated downtime to patch the vulnerability is 6 hours per production line. What is the most appropriate risk treatment decision?

    Select an answer first
  3. 33application · medium

    A chemical plant has implemented a risk mitigation plan that includes new firewall rules and access controls. The security manager wants to ensure that the controls remain effective over time as the threat landscape changes. Which activity is most important to include in the ongoing risk monitoring process?

    Select an answer first
  4. 34application · medium

    A pipeline company has implemented a risk monitoring program. They receive daily alerts from their IDS, but the security team is overwhelmed and often misses critical alerts. What is the most effective improvement to their risk monitoring process?

    Select an answer first
  5. 35application · medium · select all that apply

    A municipal water treatment plant has identified several vulnerabilities during a risk assessment. Which of the following are common threats/vulnerabilities specific to ICS/SCADA environments that should be considered? Select all that apply.

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.