Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 8Objective 2

Types of IDS (Network, Host, Network Node) ICSSCADA Practice Questions (Page 1)

Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
4concepts

Questions 1–5

  1. 1application · medium

    A regional power utility has a substation with a single critical protection relay that communicates with a central SCADA master over a dedicated serial link. The relay has no logging capability and cannot run any third-party software. The security team needs to detect malicious commands sent to this relay without affecting the serial communication. Which approach best fits the constraint?

    Select an answer first
  2. 2application · medium

    A water utility has a flat Layer 2 network with a single core switch connecting all OT devices, a historian, and the engineering workstations. The security team wants to detect malware beaconing outbound to the internet and lateral movement between OT zones, but they cannot install agents on the legacy PLCs and RTUs. Which deployment provides the broadest visibility with the least operational impact?

    Select an answer first
  3. 3expert · medium

    A pipeline company has a control network with multiple segments. They have a NIDS on the main backbone, but they suspect a specific pump station is being targeted. They want to increase visibility into that station's traffic without affecting the rest of the network. Which action is most effective?

    Select an answer first
  4. 4foundation · easy

    Which monitoring source is a host-based IDS (HIDS) designed to analyze?

    Select an answer first
  5. 5application · medium

    A pharmaceutical company has a historian server that stores batch records. Compliance requires detecting any unauthorized change to the server's configuration files or system logs. The server is in a secured VLAN with limited network monitoring. Which IDS type is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.