
EC-CouncilICS/SCADA Cybersecurity
Domain 4Objective 5
Vulnerability Scanners ICSSCADA Practice Questions (Page 6)
Part of the Vulnerability Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
5concepts
Questions 26–30
- 26
After a vulnerability scanner identifies a vulnerability on an ICS/SCADA device, what is the next step in an effective vulnerability management workflow?
Select an answer first - 27
What is a key advantage of passive vulnerability scanning over active scanning in an ICS/SCADA environment?
Select an answer first - 28
When deploying a vulnerability scanner in an ICS/SCADA network, which practice is most important to avoid disrupting critical processes?
Select an answer first - 29
A vulnerability scan of a wastewater treatment plant's SCADA network produced a large number of false positives, overwhelming the security team. The false positives are mostly due to the scanner detecting outdated software versions that are actually patched via vendor-specific hotfixes not recognized by the scanner. What should the team do to improve scan accuracy?
Select an answer first - 30
After a vulnerability scan, the security team identifies a critical vulnerability in a PLC. The remediation requires a firmware update that can only be performed during a plant shutdown. What should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.