
EC-CouncilICS/SCADA Cybersecurity
Domain 6Objective 4
Selecting and Applying Controls to Mitigate Risk ICSSCADA Practice Questions (Page 6)
Part of the Securing the ICS Network domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 26–30
- 26
A natural gas pipeline company has implemented a defense-in-depth strategy with firewalls, IDS, and access controls. However, a recent penetration test revealed that an attacker could bypass the IDS by using encrypted traffic. Which additional control would best address this gap?
Select an answer first - 27
In a defense-in-depth approach for an ICS, which combination of controls represents a layered strategy?
Select an answer first - 28
A hospital's building management system (BMS) controls HVAC and access doors. The BMS is managed by an external vendor who requires remote access for maintenance. The hospital's security policy requires least privilege and accountability, but the vendor insists on using a shared account for simplicity. What is the best way to satisfy both the vendor and the security policy?
Select an answer first - 29
Which of the following is a common implementation of network zoning in an ICS?
Select an answer first - 30
A wastewater treatment plant has deployed a network intrusion detection system (NIDS) on the control network. The security analyst notices that the NIDS generates many false positives due to legitimate broadcast traffic from the PLCs. The analyst wants to reduce the noise while still detecting real threats. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.