Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilICS/SCADA Cybersecurity

Domain 8Objective 1

What IDS Can and Cannot Do ICSSCADA Practice Questions (Page 4)

Part of the Intrusion Detection and Prevention Systems (IDS/IPS) domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–7 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
5concepts

Questions 16–20

  1. 16application · medium

    An ICS security analyst notices that the IDS generates hundreds of alerts per day for 'Modbus function code 90' (which is not a standard function code) from a particular vendor's HMI. After investigation, the analyst confirms these are normal heartbeat messages from the HMI. The analyst wants to reduce noise while still detecting real attacks. What should the analyst do?

    Select an answer first
  2. 17expert · hard

    A water utility has a network-based IDS monitoring the SCADA network. The security team wants to detect attacks that originate from the corporate network and target the PLCs. The corporate network uses a mix of encrypted and unencrypted protocols. The team is considering placing the IDS at the boundary between the corporate and SCADA networks, or inside the SCADA network. What is the best placement to maximize detection of these attacks?

    Select an answer first
  3. 18expert · hard

    A large ICS environment has multiple network segments, including a DMZ, a control network, and a field network. The security team wants to deploy IDS sensors to monitor all segments. They have a limited budget and can only deploy a few sensors. What is the most important consideration when deciding where to place the sensors?

    Select an answer first
  4. 19foundation · easy

    What is the impact of a high rate of false positives on an IDS deployment in an ICS environment?

    Select an answer first
  5. 20application · medium

    A water utility deployed a network-based IDS at the boundary between the IT and OT networks. The security team notices that the IDS generates no alerts for a series of malicious Modbus commands that originate from a compromised engineering workstation and are sent to a PLC. The commands are valid Modbus function codes but use unusual register addresses. What is the most likely reason the IDS failed to alert?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ICSSCADA” is a trademark of its owner, used for identification only.