
EC-CouncilICS/SCADA Cybersecurity
Domain 8Objective 1
What IDS Can and Cannot Do ICSSCADA Practice Questions (Page 2)
Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
Questions 6–10
- 6
A security team at a pharmaceutical plant is evaluating the effectiveness of their network-based IDS. The IDS has a low false-positive rate, but the team suspects it is missing attacks. An investigation reveals that the IDS is not detecting attacks that use legitimate protocols, such as an attacker using a valid engineering workstation to send unauthorized commands. What is the most likely reason for this gap?
Select an answer first - 7
A security analyst is tuning an IDS rule that detects unauthorized access to a historian database. The rule currently has a high false-positive rate because it triggers on legitimate read-only queries. The analyst wants to reduce false positives without missing real attacks. What is the best approach?
Select an answer first - 8
An ICS security team plans to deploy a network-based IDS to monitor traffic between the corporate network and the SCADA DMZ. Which placement would maximize the IDS's ability to detect external attacks?
Select an answer first - 9
A large ICS environment has a mix of legacy and modern devices. The security team deploys a network-based IDS that uses both signature and anomaly detection. The IDS generates a high number of alerts for legitimate but unusual traffic patterns from a new PLC model. The team is concerned about missing real attacks due to alert fatigue. They have limited staff and cannot manually tune rules for every device. What is the best approach to reduce false positives while maintaining detection capability?
Select an answer first - 10
In an ICS network, an analyst notices that a security device is placed inline between the SCADA firewall and the switch, and it can drop malicious packets. Which type of device is this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.