Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 1Objective 6

Security Policy ICSSCADA Practice Questions (Page 5)

Part of the Introduction to ICS/SCADA Network Defense domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
4concepts

Questions 21–25

  1. 21application · medium

    A power generation company's security policy mandates that all OT network changes be approved by the change advisory board (CAB). A shift engineer discovers a critical safety vulnerability and patches a PLC directly, bypassing the CAB, to prevent a potential explosion. The patch is successful. How should the compliance team handle this situation to best support both safety and policy adherence?

    Select an answer first
  2. 22expert · hard

    A water utility's security policy requires all remote access to the SCADA network to use a VPN with multi-factor authentication. During a storm, a senior operator needs to access the system from home, but the MFA token is not working. The operator calls the IT helpdesk, which is closed. The operator's supervisor authorizes access without MFA to restore critical water pressure. What should the compliance team do after the incident?

    Select an answer first
  3. 23expert · hard

    A pharmaceutical company is developing a security policy for its ICS environment. The company must comply with FDA regulations that require validation of any software changes. The IT security team wants to implement automated patch deployment to all control-system servers. The control engineering team objects, stating that automated patching could disrupt validated processes. The compliance officer notes that unpatched systems may violate FDA requirements for security controls. What is the best approach to reconcile these conflicting requirements?

    Select an answer first
  4. 24application · medium

    A pipeline operator's security policy states that all configuration changes to the OT network must be approved through a change-management ticket. During an audit, the reviewer finds that a control-system engineer applied a firmware update without a ticket, citing an urgent vendor advisory. The update was successful and no incident occurred. What should the compliance team do to best align with the policy's enforcement approach?

    Select an answer first
  5. 25expert · hard

    A pharmaceutical manufacturer has a security policy that requires all OT personnel to use individual accounts. However, a legacy packaging line uses a shared 'admin' account because the vendor's software does not support individual logins. The compliance team must enforce the policy without halting production. Which approach best satisfies both policy compliance and operational continuity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.