
EC-CouncilICS/SCADA Cybersecurity
Domain 6Objective 4
Selecting and Applying Controls to Mitigate Risk ICSSCADA Practice Questions (Page 4)
Part of the Securing the ICS Network domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 16–20
- 16
An ICS security team wants to detect an attacker who has moved laterally from the IT network into the OT network and is attempting to communicate with a historian server. The team has a limited budget and cannot deploy new hardware. Which monitoring control is most appropriate?
Select an answer first - 17
A food processing plant has a risk assessment that identifies a high risk of unauthorized personnel gaining physical access to the control room and connecting a laptop to the engineering network. Which combination of controls best mitigates this risk?
Select an answer first - 18
A water treatment facility has a flat network where the SCADA HMI, PLCs, and engineering workstations all share the same subnet. The plant manager wants to reduce the risk of a malware infection spreading from the corporate IT network to the process control network. You are asked to implement a segmentation plan that isolates the process control network while still allowing the engineering team to remotely access the HMI for troubleshooting. Which approach best meets the requirement?
Select an answer first - 19
A pharmaceutical plant has a validated process control network that must remain compliant with good manufacturing practices (GMP). The plant wants to implement network segmentation to improve security, but any change to the network could require revalidation. What is the best approach?
Select an answer first - 20
A regional airport has a baggage handling ICS that is connected to the corporate IT network for reporting. A risk assessment shows that a ransomware infection on the IT network could spread to the ICS and halt operations. The airport cannot afford to completely disconnect the ICS from the IT network because the reporting is required by regulators. Which control strategy best balances the need for reporting with the need to protect the ICS?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.