Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 8Objective 1

What IDS Can and Cannot Do ICSSCADA Practice Questions (Page 1)

Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
5concepts

Questions 1–5

  1. 1application · medium

    A water treatment facility uses a network-based IDS that relies on signatures for known exploits. An attacker uses a previously unknown vulnerability in the HMI software to send a crafted packet that causes the HMI to crash. The IDS does not alert. What is the most likely reason?

    Select an answer first
  2. 2application · medium

    A water utility has a network-based IDS placed on a tap between the SCADA server and the PLC network. The IDS is configured to detect Modbus anomalies. The security team notices that the IDS does not see any traffic from the engineering workstation that is on a separate VLAN but routed through the same switch. What is the most likely reason?

    Select an answer first
  3. 3application · medium

    A hospital's ICS network uses a network-based IDS. The security team is evaluating whether the IDS can detect an attacker who has gained control of a nurse's workstation and is using a legitimate remote desktop protocol (RDP) session to access the building management system. What is the most accurate assessment of the IDS's ability in this scenario?

    Select an answer first
  4. 4application · medium

    A power utility has a network-based IDS monitoring the DMZ between the corporate network and the control network. The security team wants to automatically stop a known malware signature from spreading to the control network. What should they do?

    Select an answer first
  5. 5expert · hard

    A security analyst at a natural gas pipeline is tuning the IDS. The IDS currently has a high false-positive rate, causing operators to ignore alerts. The analyst must reduce false positives, but the operations team requires that no legitimate maintenance activity be blocked or delayed. The analyst is considering increasing the threshold for a specific rule that detects unusual Modbus writes. What is the most important trade-off to consider?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.