
EC-CouncilICS/SCADA Cybersecurity
Domain 8Objective 2
Types of IDS (Network, Host, Network Node) ICSSCADA Practice Questions (Page 4)
Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
4concepts
Questions 16–20
- 16
A manufacturing company has a segmented OT network with a DMZ between IT and OT. The security team wants to detect an attacker who has already compromised a workstation in the OT zone and is using it to pivot to other OT devices. The team can deploy only one IDS sensor. Which placement gives the best chance of detecting the pivot?
Select an answer first - 17
A pharmaceutical company's OT network is air-gapped from the corporate IT network. The security team is concerned about a rogue engineer using a USB drive to load unauthorized firmware onto a specific batch controller. The controller does not support any monitoring agent, but the Windows-based engineering workstation used to program it does. Which control would directly detect the unauthorized firmware change?
Select an answer first - 18
A water utility has a critical server that runs a proprietary SCADA application. The server is in a secured VLAN with a NIDS monitoring the VLAN. The security team is concerned about an insider with local access to the server. They want to detect any modification to the application binaries or configuration files. Which approach is best?
Select an answer first - 19
A hospital's building automation system (BAS) uses a Windows server to manage HVAC controllers. The security team suspects that an attacker has been tampering with the server's configuration files and scheduled tasks over the past month. The server is not generating any network traffic that would indicate a remote attack. Which IDS capability would provide the most direct evidence of this local tampering?
Select an answer first - 20
A regional electrical utility operates a control center with a flat Ethernet network. The security team must detect two threats: (1) an insider who has physical access to a Windows-based engineering workstation and plans to modify the historian's database, and (2) an external attacker who has breached the corporate firewall and is sending malformed IEC 61850 packets to a protection relay. The team has a limited budget and can deploy only one type of sensor. Which sensor type provides the best combined coverage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.