Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 6Objective 3

Securing the Protocols Unique to the ICS ICSSCADA Practice Questions (Page 5)

Part of the Securing the ICS Network domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
5concepts

Questions 21–25

  1. 21application · medium

    A water utility is deploying a new Modbus TCP network between a control center and several remote pumping stations. The network will be isolated from the corporate IT network. The security team wants to prevent unauthorized devices from joining the Modbus network. Which deployment control is most appropriate?

    Select an answer first
  2. 22expert · hard

    A water utility has a mix of Modbus TCP and DNP3 devices. The security team is implementing a new security policy that requires all control commands to be authenticated. The Modbus devices do not support any authentication, and the DNP3 devices support Secure Authentication. The team has a limited budget and cannot replace the Modbus devices. What is the most effective way to meet the policy for the Modbus devices?

    Select an answer first
  3. 23application · medium

    A security engineer is reviewing the configuration of a Modbus TCP network and notices that the PLCs are accepting connections from any source IP. The engineer also notices that the SCADA server uses a fixed function code to read data. What is the most significant vulnerability in this configuration?

    Select an answer first
  4. 24application · medium

    A manufacturing plant uses OPC UA for data exchange between a historian and multiple PLCs. The security team wants to detect an attacker who is replaying captured OPC UA messages to alter setpoints. Which monitoring approach is most effective?

    Select an answer first
  5. 25expert · hard

    A security analyst is investigating a suspected attack on a Modbus TCP network. The analyst sees a series of Modbus read requests from a single source IP to multiple PLCs, each request reading a different register range. The requests are occurring at a rate much higher than normal. What is the most likely explanation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.