
EC-CouncilICS/SCADA Cybersecurity
Domain 8Objective 1
What IDS Can and Cannot Do ICSSCADA Practice Questions (Page 3)
Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
Questions 11–15
- 11
An ICS security team has tuned their IDS to be very sensitive, resulting in a high number of alerts. The team is overwhelmed and has started ignoring alerts. What is the most likely consequence?
Select an answer first - 12
Which deployment consideration is most important for a network-based IDS to effectively detect threats in an ICS environment?
Select an answer first - 13
A power plant has a network-based IDS placed on a SPAN port of the core switch. The security team is concerned about attacks that use fragmented IP packets to evade detection. What is the most effective way to improve the IDS's ability to detect such attacks?
Select an answer first - 14
An ICS security analyst deploys a network-based IDS at the boundary between the corporate network and the SCADA DMZ. Which core function will this IDS perform?
Select an answer first - 15
A chemical plant has an IDS that monitors the control network. The security manager wants to automatically block a specific IP address that is sending malformed packets to a PLC. What is the most appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.