
EC-CouncilICS/SCADA Cybersecurity
Domain 8Objective 2
Types of IDS (Network, Host, Network Node) ICSSCADA Practice Questions (Page 3)
Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
4concepts
Questions 11–15
- 11
A food processing plant has a single critical packaging machine that communicates with a PLC over a dedicated point-to-point Ethernet link. The machine's vendor refuses to allow any inline security device that could introduce latency. The security team wants to detect an attacker sending unauthorized setpoints to the PLC over this link. Which deployment satisfies the vendor's constraint?
Select an answer first - 12
A host-based IDS (HIDS) is installed on an engineering workstation in an ICS environment. Which activity is the HIDS most likely to monitor?
Select an answer first - 13
A security analyst is planning to deploy a Network-based IDS (NIDS) in an ICS environment. Which deployment location is most typical for a NIDS sensor?
Select an answer first - 14
How does a Network Node IDS (NNIDS) differ from a traditional Network-based IDS (NIDS)?
Select an answer first - 15
An engineer wants to monitor all traffic to and from a specific RTU that uses a proprietary protocol. The RTU is on a segment with many other devices, and the engineer only cares about this one node. Which IDS type is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.