
EC-CouncilICS/SCADA Cybersecurity
Domain 4Objective 5
Vulnerability Scanners ICSSCADA Practice Questions (Page 4)
Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
5concepts
Questions 16–20
- 16
What is the purpose of mapping vulnerability scan results to ICS/SCADA assets?
Select an answer first - 17
A vulnerability scan of a nuclear research facility's control system identified a high-severity vulnerability in a radiation monitoring system. The system is connected to the corporate network for data reporting. The same vulnerability exists on a standalone calibration device that is not networked. The facility has limited resources for remediation. Which vulnerability should be remediated first?
Select an answer first - 18
After remediating a vulnerability, what is the next step in the vulnerability management workflow?
Select an answer first - 19
An ICS security analyst is configuring a vulnerability scanner for a power utility's distribution network. The network contains a mix of modern Ethernet-based IEDs and older serial-to-Ethernet converters. The analyst wants to minimize the risk of disrupting operations while still obtaining useful vulnerability data. Which configuration should the analyst apply?
Select an answer first - 20
Which type of vulnerability scanner is most suitable for an ICS/SCADA environment where continuous monitoring is required but network traffic must not be disrupted?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.