Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 1Objective 6

Security Policy ICSSCADA Practice Questions (Page 4)

Part of the Introduction to ICS/SCADA Network Defense domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
4concepts

Questions 16–20

  1. 16application · medium

    A utility is updating its security policy to address new regulatory requirements for critical infrastructure. The policy team has drafted the updated document and received feedback from stakeholders. What is the next step in the policy maintenance process?

    Select an answer first
  2. 17application · medium

    An electric utility is writing a security policy for its distribution automation system. The policy team is debating which elements must be included. The compliance officer wants a list of specific firewall brand names, while the OT manager wants a statement of which systems are covered. Which combination of components should the policy actually contain?

    Select an answer first
  3. 18application · medium

    A mid-sized utility is creating its first ICS security policy. The project sponsor wants to draft the document in one week and publish it without review. The security lead objects, citing the need for a structured development process. Which sequence best represents the correct policy development lifecycle?

    Select an answer first
  4. 19application · medium

    A pipeline company's security policy states that 'all remote access to the SCADA network must be through the approved VPN gateway.' An engineer connects directly to a field device using a cellular modem to troubleshoot a problem. What does this scenario illustrate?

    Select an answer first
  5. 20expert · hard

    A natural gas pipeline company has a security policy that assigns the control systems manager responsibility for approving all changes to the SCADA system. The IT security team has identified a critical vulnerability in the SCADA server and wants to apply an emergency patch. The control systems manager is on leave for two weeks. The pipeline is operating normally. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.