Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 4Objective 5

Vulnerability Scanners ICSSCADA Practice Questions (Page 1)

Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
5concepts

Questions 1–5

  1. 1application · medium

    A vulnerability scan of a hospital's building management system (BMS) reported a critical vulnerability in a HVAC controller. The controller is running a firmware version that is no longer supported. The hospital cannot replace the controller immediately. What should the security team do to reduce the risk?

    Select an answer first
  2. 2application · medium

    A security team at a food processing company has integrated its vulnerability scanner with a ticketing system. After a scan, the team wants to ensure that each identified vulnerability is tracked through remediation. Which practice best supports this workflow?

    Select an answer first
  3. 3application · medium

    A vulnerability scan report shows a vulnerability in a safety instrumented system (SIS) controller. The SIS is critical for plant safety. What is the most appropriate action?

    Select an answer first
  4. 4expert · hard

    A security analyst is configuring a vulnerability scanner for a petrochemical plant's OT network. The plant has a mix of Windows-based HMIs and legacy PLCs. The analyst must minimize false positives while also ensuring that critical vulnerabilities are not missed. The scanner currently reports many false positives on the HMIs because it does not recognize vendor-specific security updates. What should the analyst do?

    Select an answer first
  5. 5application · medium

    A power generation company wants to assess the security of its substation automation network, which uses IEC 61850 protocols. The network is highly available and cannot tolerate any downtime. The security team is considering using a vulnerability scanner. Which approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.