EC-Council ICS/SCADA Cybersecurity Certification — Questions and Answers
Question 1: An ICS technician finds an unattended USB drive near a substation entrance. According to best practice, what should they do?
- Leave it in place and report the location via radio
- Plug it into an air-gapped workstation to identify the owner
- Dispose of it in the nearest trash receptacle
- Submit it to the security team without connecting it to any device (Correct answer)
Correct answer: Submit it to the security team without connecting it to any device
Unattended media should be treated as potentially malicious and turned in to security personnel without being connected to any system.
Question 2: Which physical access control measure is specifically designed to prevent 'tailgating' into secured ICS control rooms?
- CCTV cameras at the entrance
- Badge readers on all interior office doors
- Security guard stationed 100 meters from the building
- Mantrap (airlock) vestibule requiring individual authentication for each person (Correct answer)
Correct answer: Mantrap (airlock) vestibule requiring individual authentication for each person
A mantrap uses two interlocked doors where only one can open at a time, physically preventing a second person from entering behind an authenticated user without presenting their own credentials.
Question 3: An ICS facility uses wireless sensors for remote area monitoring. Which security control is MOST critical to implement for these devices?
- Using the highest available wireless transmission power
- Mutual authentication and encrypted communications between sensors and the gateway (Correct answer)
- Disabling firmware update capability to prevent tampering
- Connecting wireless sensors directly to the corporate Wi-Fi network
Correct answer: Mutual authentication and encrypted communications between sensors and the gateway
Wireless ICS sensors must use mutual authentication to prevent rogue device insertion and encryption to prevent eavesdropping or data manipulation.
Question 4: Which legal authority allows U.S. federal agencies to direct ICS operators at private utilities to take specific protective actions during a declared national cyber emergency?
- Defense Production Act and National Emergencies Act (Correct answer)
- Presidential Policy Directive 21 (PPD-21)
- Section 9 of Executive Order 13636
- Section 215 of the USA PATRIOT Act
Correct answer: Defense Production Act and National Emergencies Act
The Defense Production Act and National Emergencies Act grant the President authority to direct private sector actions, including ICS operators, during declared national emergencies.
Question 5: What does SCADA stand for in the context of industrial control systems?
- Security Control And Data Acquisition
- Supervisory Control And Data Acquisition (Correct answer)
- System Command And Data Authorization
- Supervisory Command And Data Analysis
Correct answer: Supervisory Control And Data Acquisition
SCADA stands for Supervisory Control And Data Acquisition, referring to systems that monitor and control industrial infrastructure.
Question 6: An ICS operator discovers ransomware is spreading through their OT network. Which action is legally required under CIRCIA 2022 for covered critical infrastructure entities?
- Obtain a court order before isolating systems
- Report the incident to CISA within 72 hours (Correct answer)
- Notify all customers within 24 hours
- Immediately shut down all ICS operations
Correct answer: Report the incident to CISA within 72 hours
CIRCIA 2022 requires covered critical infrastructure entities to report significant cyber incidents to CISA within 72 hours of discovery.
Question 7: Which NIST SP 800-82 revision introduced specific guidance for cloud-based OT systems and IoT/IIoT devices?
- Revision 3 (2023) (Correct answer)
- Original publication (2006)
- Revision 2 (2015)
- Revision 1 (2011)
Correct answer: Revision 3 (2023)
NIST SP 800-82 Revision 3 (2023) significantly expanded coverage to include cloud-based OT, IoT/IIoT, and modern threats not addressed in earlier revisions.
Question 8: Why should ICS emergency response procedures explicitly address the scenario of GPS timing signal spoofing?
- Because many ICS components rely on GPS timing for synchronization, and spoofing can disrupt time-sensitive control operations (Correct answer)
- Because GPS encryption requires special incident handling
- Because GPS is used for physical security of ICS facilities
- Because GPS vendors require notification within 24 hours of any disruption
Correct answer: Because many ICS components rely on GPS timing for synchronization, and spoofing can disrupt time-sensitive control operations
GPS timing is used by many ICS components (e.g., protection relays, SCADA timestamps) and spoofing can cause synchronization failures leading to control system errors.
Question 9: What is the primary cybersecurity concern with wireless protocols such as WirelessHART or ISA100.11a when used in ICS environments?
- They introduce RF-based eavesdropping, jamming, and rogue device risks if not properly secured (Correct answer)
- They require Internet connectivity to function
- They reduce process data update rates below acceptable thresholds
- They are incompatible with most PLC vendors
Correct answer: They introduce RF-based eavesdropping, jamming, and rogue device risks if not properly secured
Wireless ICS protocols can be jammed to cause denial-of-service, eavesdropped to gather process intelligence, or spoofed by rogue devices if encryption and authentication are not enforced.
Question 10: Which concept BEST describes the communication failure when ICS security teams and operations teams each assume the other is monitoring a specific system, resulting in no one monitoring it?
- Responsibility gap caused by ambiguous ownership (Correct answer)
- Denial of service from internal misconfiguration
- Zero-day exploitation of monitoring software
- Defense-in-depth failure
Correct answer: Responsibility gap caused by ambiguous ownership
Ambiguous ownership creates gaps where no team takes responsibility, a common ICS security failure mode resolvable through clear RACI assignments.
Question 11: What is 'deep packet inspection' (DPI) most useful for in ICS surveillance?
- Analyzing the payload of industrial protocol messages to detect malicious commands (Correct answer)
- Increasing the speed of network traffic through the ICS network
- Encrypting communications between PLCs and HMIs
- Compressing historian data for more efficient storage
Correct answer: Analyzing the payload of industrial protocol messages to detect malicious commands
DPI enables inspection of industrial protocol payloads (e.g., Modbus function codes) to detect unauthorized commands that would appear normal at the packet header level.
Question 12: Which EtherNet/IP security feature provides authentication and encryption for industrial Ethernet devices running CIP protocol?
- PROFINET Security Class 3
- DNP3 Secure Authentication
- CIP Security using TLS/DTLS (Correct answer)
- Modbus/TCP encryption extension
Correct answer: CIP Security using TLS/DTLS
CIP Security extends EtherNet/IP with TLS (TCP) and DTLS (UDP) to provide device authentication and encrypted communication.
Question 13: Which protocol is commonly used for secure remote access tunneling into ICS environments?
- Telnet
- TFTP
- IPsec VPN (Correct answer)
- FTP
Correct answer: IPsec VPN
IPsec VPN provides encrypted, authenticated tunnels for secure remote access into ICS environments.
Question 14: Why is staying current with industry developments important for Industrial Control Systems Security professionals?
- Only academic researchers need to stay current
- It is only important for certification renewal
- Industry changes rarely affect practice
- To provide the best possible service using current knowledge and practices (Correct answer)
Correct answer: To provide the best possible service using current knowledge and practices
Staying current ensures professionals provide the best possible service by incorporating the latest knowledge, techniques, and regulatory requirements.
Question 15: What is the difference between monitoring and observability?
- Monitoring tracks known metrics while observability enables investigation of unknown issues (Correct answer)
- Observability replaces the need for monitoring
- They are identical concepts
- Monitoring is for hardware, observability is for software
Correct answer: Monitoring tracks known metrics while observability enables investigation of unknown issues
Monitoring tracks predefined metrics, while observability provides the tooling and data to investigate unexpected or unknown issues through logs, traces, and metrics.
Question 16: An industrial facility installs seismic sensors around its perimeter fence. What type of intrusion detection does this represent?
- Volumetric detection using microwave beams
- Line detection using infrared beams
- Active detection using transmitted energy
- Passive detection using ground vibration analysis (Correct answer)
Correct answer: Passive detection using ground vibration analysis
Seismic sensors passively detect ground vibrations caused by footsteps or vehicles without emitting any signal themselves.
Question 17: What is the purpose of maintaining a 'golden image' or known-good backup of ICS software configurations?
- To test new features before deployment
- To satisfy software licensing requirements
- To share configurations with vendors for support
- To enable rapid restoration of systems to a verified secure state after an incident (Correct answer)
Correct answer: To enable rapid restoration of systems to a verified secure state after an incident
Known-good configuration backups allow rapid and confident restoration of ICS systems to a trusted state after malware removal or system compromise.
Question 18: In the PURDUE model for ICS architecture, which level contains the SCADA servers and historians that aggregate monitoring data?
- Level 1 – Basic Control
- Level 3 – Manufacturing Operations Management (Correct answer)
- Level 4 – Business Planning and Logistics
- Level 0 – Field Level
Correct answer: Level 3 – Manufacturing Operations Management
Level 3 of the Purdue model houses SCADA servers, historians, and manufacturing execution systems that collect and store process monitoring data.
Question 19: What should be done if an error is discovered in existing records?
- Draw a single line through the error, note the correction, date, and initial (Correct answer)
- Remove the page and rewrite it
- Use correction fluid to cover the error
- Ignore the error if it seems minor
Correct answer: Draw a single line through the error, note the correction, date, and initial
The correct method is a single line through the error with a dated and initialed correction, preserving the original entry for legal and audit purposes.
Question 20: What is the principle of least privilege?
- Restricting access only for external users
- Granting users only the minimum access necessary to perform their duties (Correct answer)
- Removing all access until requested
- Giving all users administrator access for convenience
Correct answer: Granting users only the minimum access necessary to perform their duties
The principle of least privilege limits access to the minimum necessary for job functions, reducing the attack surface and potential impact of compromised accounts.
Question 21: What ICS-specific network protocol operates over serial communication and uses function codes to read/write registers on remote devices?
- Foundation Fieldbus
- EtherNet/IP
- PROFINET
- Modbus RTU (Correct answer)
Correct answer: Modbus RTU
Modbus RTU uses serial communication with function codes (e.g., FC03 for read holding registers) to interact with PLCs and other field devices.
Question 22: What logging feature is most critical for forensic investigation of a suspected ICS cyberattack that manipulated sensor readings?
- Periodic manual log exports to a USB drive
- Compressed log archives with weekly rotation
- Logs stored locally on the affected HMI workstation
- Tamper-evident, time-synchronized logs stored on a write-once medium or remote SIEM (Correct answer)
Correct answer: Tamper-evident, time-synchronized logs stored on a write-once medium or remote SIEM
Tamper-evident logs with precise time synchronization stored off the compromised system are essential for reliable forensic reconstruction of attack timelines.
Question 23: During an ICS vulnerability assessment, a scanner detects an open port 102 on a device. What protocol and associated risk should the analyst investigate?
- EtherNet/IP — susceptibility to Allen-Bradley device spoofing
- DNP3 — susceptibility to unauthorized SCADA commands
- S7comm — susceptibility to Siemens PLC manipulation (Correct answer)
- BACnet — susceptibility to building automation hijacking
Correct answer: S7comm — susceptibility to Siemens PLC manipulation
Port 102 is used by S7comm, the Siemens S7 PLC communication protocol, and represents a significant risk as it can be exploited to read/write memory, start/stop PLCs, and was the protocol targeted by Stuxnet.
Question 24: Which NIST publication provides a cybersecurity framework commonly referenced for ICS and critical infrastructure protection?
- NIST SP 800-37
- NIST SP 800-171
- NIST SP 800-82 (Correct answer)
- NIST SP 800-53
Correct answer: NIST SP 800-82
NIST SP 800-82 is the Guide to Industrial Control System Security specifically tailored for ICS environments including SCADA and DCS.
Question 25: Which documentation practice best supports legal defensibility?
- Subjective opinions about client behavior
- Brief notes using abbreviations
- Copying previous entries to save time
- Objective, factual entries with specific measurements and timestamps (Correct answer)
Correct answer: Objective, factual entries with specific measurements and timestamps
Objective, factual entries with specific measurements and timestamps provide the strongest legal defense by demonstrating thorough, unbiased professional practice.
Question 26: Under the NIST SP 800-53 control family, which control family is MOST directly applicable to ICS physical access to control rooms?
- Physical and Environmental Protection (PE) (Correct answer)
- Identification and Authentication (IA)
- System and Communications Protection (SC)
- Access Control (AC)
Correct answer: Physical and Environmental Protection (PE)
The Physical and Environmental Protection (PE) control family in NIST SP 800-53 addresses physical access controls, monitoring, and protection of facilities housing information systems.
Question 27: During an ICS incident, the FIRST priority for the incident response team should be:
- Restore normal operations as quickly as possible
- Preserve forensic evidence for later analysis
- Notify law enforcement and regulatory bodies
- Ensure safety of personnel and prevent physical harm (Correct answer)
Correct answer: Ensure safety of personnel and prevent physical harm
In ICS environments, safety of personnel and prevention of physical harm always takes precedence over other incident response objectives.
Question 28: In a semi-quantitative ICS risk assessment, an analyst assigns a likelihood score of 3 (on a 1-5 scale) and a consequence score of 5. A proposed control reduces consequence to 3. What is the percentage reduction in risk score?
- 60%
- 40% (Correct answer)
- 20%
- 33%
Correct answer: 40%
Original risk = 3×5=15; residual risk = 3×3=9; reduction = (15-9)/15 = 6/15 = 40%, illustrating how consequence reduction controls can significantly lower overall risk.
Question 29: What is the NERC CIP-006 standard primarily concerned with?
- Incident response planning for grid operators
- Physical security of BES Cyber Systems at electric utilities (Correct answer)
- Personnel training and security awareness
- Network security monitoring for BES Cyber Systems
Correct answer: Physical security of BES Cyber Systems at electric utilities
NERC CIP-006 establishes requirements for physical security plans, access controls, and monitoring for Bulk Electric System Cyber Systems.
Question 30: What is the most important principle in professional Industrial Control Systems Security practice?
- Working as quickly as possible
- Maintaining competence through continuous learning and adherence to standards (Correct answer)
- Following only personal judgment
- Maximizing revenue from each client
Correct answer: Maintaining competence through continuous learning and adherence to standards
Maintaining competence through continuous learning and adherence to professional standards ensures quality service delivery and public protection in Industrial Control Systems Security practice.
Question 31: A private security guard at a water treatment plant discovers an unauthorized person tampering with PLCs. Under what legal principle may the guard physically detain the individual?
- Sovereign immunity
- NERC CIP enforcement authority
- Citizen's arrest authority under state law (Correct answer)
- Federal law enforcement deputization
Correct answer: Citizen's arrest authority under state law
Private security personnel may detain individuals under citizen's arrest provisions of applicable state law when witnessing a crime in progress.
Question 32: How should monitoring alerts be configured?
- Only for critical system failures
- With no thresholds to capture everything
- With meaningful thresholds that indicate actionable conditions (Correct answer)
- To alert on every minor deviation
Correct answer: With meaningful thresholds that indicate actionable conditions
Meaningful thresholds prevent alert fatigue while ensuring actionable conditions are caught, enabling timely response to genuine issues.
Question 33: A risk analyst is documenting that an ICS vulnerability cannot be patched because the vendor no longer supports the system. Which risk treatment approach is most appropriate for this scenario?
- Risk acceptance with documented compensating controls (Correct answer)
- Risk avoidance by immediately shutting down the system
- Risk transference by selling the asset
- Risk mitigation through vendor-supplied patches
Correct answer: Risk acceptance with documented compensating controls
When patching is impossible due to end-of-life status, the standard approach is formal risk acceptance with documented compensating controls (network segmentation, monitoring, procedural controls) to reduce exposure while maintaining operations.
Question 34: Which NIST publication serves as the primary guide for securing Industrial Control Systems?
- NIST SP 800-61
- NIST SP 800-82 (Correct answer)
- NIST SP 800-171
- NIST SP 800-53
Correct answer: NIST SP 800-82
NIST SP 800-82 'Guide to Industrial Control Systems (ICS) Security' provides guidance specific to SCADA, DCS, and PLC systems, including risk management and countermeasures tailored to OT environments.
Question 35: What is 'defense in depth' as applied to ICS cybersecurity?
- Focusing all security resources exclusively on the most critical PLCs
- Deploying a single, extremely robust security control at the network perimeter
- Applying multiple overlapping layers of security controls so that failure of one layer does not result in total compromise (Correct answer)
- Requiring antivirus software on all ICS endpoints regardless of impact on operations
Correct answer: Applying multiple overlapping layers of security controls so that failure of one layer does not result in total compromise
Defense in depth applies multiple independent security layers — physical controls, network segmentation, authentication, monitoring — so that an attacker must defeat several barriers to cause harm.
Question 36: When documenting an ICS incident, what is the primary purpose of a chain-of-custody log?
- To track who accessed or handled evidence to preserve its integrity (Correct answer)
- To record the timeline of system downtime
- To document vendor notifications during the incident
- To list all personnel who responded to the incident
Correct answer: To track who accessed or handled evidence to preserve its integrity
Chain-of-custody logs ensure evidence integrity by recording every person who handled evidence, which is critical for legal proceedings.
Question 37: Which document formally defines the scope and limitations of a penetration tester's authority to test an ICS environment?
- Service Level Agreement (SLA)
- Security policy
- Memorandum of Understanding (MOU)
- Rules of Engagement (ROE) (Correct answer)
Correct answer: Rules of Engagement (ROE)
Rules of Engagement define the specific boundaries, methods, and limitations authorized for a penetration test, providing legal protection for the tester.
Question 38: Which NIST publication provides guidance specifically relevant to ICS/SCADA incident response?
- NIST SP 800-171
- NIST SP 800-61
- NIST SP 800-82 (Correct answer)
- NIST SP 800-53
Correct answer: NIST SP 800-82
NIST SP 800-82 'Guide to Industrial Control Systems Security' provides ICS-specific security guidance including incident response considerations.
Question 39: Which industrial protocol is the standard for building automation systems, including HVAC, lighting, and access control?
- DNP3
- BACnet (Correct answer)
- PROFINET
- Modbus
Correct answer: BACnet
BACnet (Building Automation and Control Networks) is an ASHRAE/ISO/ANSI standard specifically developed for building automation and control systems.
Question 40: Under NERC CIP standards, what is the primary purpose of physical security controls at Electronic Security Perimeters (ESPs)?
- To establish jurisdiction for federal law enforcement
- To authorize use of lethal force against intruders
- To restrict and monitor access to cyber assets within the perimeter (Correct answer)
- To define liability limits for security personnel
Correct answer: To restrict and monitor access to cyber assets within the perimeter
NERC CIP ESP requirements focus on restricting and logging access to cyber assets to prevent unauthorized access, not on authorizing force.
Question 41: What type of malware was specifically designed to target Siemens PLCs and disrupt Iranian nuclear centrifuges?
- Triton
- BlackEnergy
- Havex
- Stuxnet (Correct answer)
Correct answer: Stuxnet
Stuxnet was a sophisticated worm discovered in 2010 that targeted Siemens S7 PLCs controlling uranium enrichment centrifuges.
Question 42: Under NERC CIP-008, what is the minimum required outcome of an incident response plan for a BES cyber security incident?
- Criminal prosecution referral to the FBI within 48 hours
- Mandatory notification of all electricity customers within 24 hours
- Roles and responsibilities, response actions, and post-incident review (Correct answer)
- Automated forensic analysis of all affected systems
Correct answer: Roles and responsibilities, response actions, and post-incident review
NERC CIP-008 requires incident response plans to document roles, responsibilities, specific response actions, and a post-incident review process for BES cyber security incidents.
Question 43: What is the purpose of a 'risk register' in ICS security documentation?
- To list all employees with system access
- To record daily system backups
- To track software licensing compliance
- To maintain a centralized log of identified risks, their likelihood, impact, and mitigation status (Correct answer)
Correct answer: To maintain a centralized log of identified risks, their likelihood, impact, and mitigation status
A risk register provides a living document that tracks each identified risk, enabling management to monitor mitigation progress over time.
Question 44: Under the Chemical Facility Anti-Terrorism Standards (CFATS), facilities must restrict access to which type of area using security measures that may include armed guards?
- Visitor parking areas
- Employee cafeterias
- Critical Asset areas with chemicals of interest (Correct answer)
- Administrative offices
Correct answer: Critical Asset areas with chemicals of interest
CFATS requires high-risk chemical facilities to restrict and control access to critical assets, particularly those involving chemicals of interest (COI) that could be weaponized.
Question 45: Which document should define who has the authority to order a controlled shutdown of an ICS during a security emergency?
- The asset inventory spreadsheet
- The IT department's change management policy
- The Incident Response Plan or Emergency Response Procedures (Correct answer)
- The vendor's equipment manual
Correct answer: The Incident Response Plan or Emergency Response Procedures
The IRP or ERP should explicitly define roles, responsibilities, and authority chains including who can authorize emergency shutdowns.
Question 46: Which aspect of ICS security does NIST SP 800-82 identify as the most significant difference from traditional IT security?
- Greater regulatory oversight of ICS environments
- Prioritization of availability and safety over confidentiality (Correct answer)
- Lack of vendor support for security patches
- Higher cost of cybersecurity tools in OT environments
Correct answer: Prioritization of availability and safety over confidentiality
NIST SP 800-82 highlights that ICS environments prioritize system availability and safety (due to physical process impacts) over confidentiality, which is the reverse of traditional IT priorities.
Question 47: Which ICS security framework recommends using 'conduits' as a concept to manage data flows between security zones in an OT environment?
- ISO 27001
- IEC 62443 (Correct answer)
- NIST SP 800-53
- COBIT 5
Correct answer: IEC 62443
IEC 62443 defines the concept of zones and conduits, where conduits are the controlled pathways through which data flows between security zones.
Question 48: What is 'crime prevention through environmental design' (CPTED) and how does it apply to ICS facilities?
- Planting trees as cover for security personnel
- Designing the physical environment to deter unauthorized access and criminal behavior (Correct answer)
- Installing environmental sensors to detect chemical threats
- Using natural ventilation to reduce HVAC attack surface
Correct answer: Designing the physical environment to deter unauthorized access and criminal behavior
CPTED uses natural surveillance, access control, and territorial reinforcement through facility design to deter threats before they reach ICS assets.
Question 49: Which legal doctrine may shield an ICS security analyst from criminal liability when accessing a system believed to be compromised, based on owner consent obtained under duress or deception?
- Implied consent
- Qualified immunity
- Necessity defense
- Mistake of fact defense (Correct answer)
Correct answer: Mistake of fact defense
A mistake of fact defense may apply when a security analyst genuinely and reasonably believed they had valid authorization, even if that belief was incorrect due to deception.
Question 50: An ICS security analyst disagrees with a vendor's recommended patch schedule for a PLC. What is the MOST appropriate first step?
- File a complaint with regulatory bodies before discussing with the vendor
- Ignore the vendor's recommendation and follow the analyst's preferred timeline
- Document the concern and request a formal technical review meeting with the vendor (Correct answer)
- Immediately apply patches on the analyst's own authority
Correct answer: Document the concern and request a formal technical review meeting with the vendor
Requesting a formal technical review ensures the concern is documented and addressed through proper channels.
Question 51: In ICS environments, what does the term 'conduit' refer to in the context of IEC 62443?
- A grouping of assets with similar security requirements
- A physical cable pathway for field wiring
- A backup power supply for control panels
- A communication pathway between two security zones (Correct answer)
Correct answer: A communication pathway between two security zones
In IEC 62443, a conduit is a logical grouping of communication channels connecting two or more security zones.
Question 52: What is the significance of professional networking in the Industrial Control Systems Security field?
- It facilitates knowledge exchange, referrals, and collaborative problem-solving (Correct answer)
- It is only useful for finding new employment
- It is only important early in one's career
- It distracts from actual work
Correct answer: It facilitates knowledge exchange, referrals, and collaborative problem-solving
Professional networking facilitates knowledge exchange, generates referrals, and enables collaborative problem-solving that improves practice quality.
Question 53: An ICS site security plan requires a 'two-person integrity' (TPI) rule for certain high-consequence areas. What does TPI prevent?
- Social engineering attacks from external visitors
- Unauthorized remote access to control systems
- Insider threats by requiring two authorized persons to be present at all times (Correct answer)
- Equipment failure by ensuring a backup technician is always present
Correct answer: Insider threats by requiring two authorized persons to be present at all times
Two-person integrity requires two qualified individuals to be present simultaneously, reducing the risk of sabotage or unauthorized actions by a single insider.
Question 54: What defines a 'zero-day' vulnerability in the context of ICS security?
- An unknown vulnerability with no available patch at the time of exploitation (Correct answer)
- A flaw that causes immediate system shutdown when triggered
- A vulnerability only exploitable within zero-trust network segments
- A vulnerability that has existed for zero days since the system was installed
Correct answer: An unknown vulnerability with no available patch at the time of exploitation
A zero-day vulnerability is unknown to the vendor or public, giving defenders zero days to patch before exploitation occurs.
Question 55: What network monitoring technique passively captures ICS protocol traffic to build a baseline of normal device behavior?
- Passive network traffic analysis (Correct answer)
- SNMP polling
- Port knocking
- Active vulnerability scanning
Correct answer: Passive network traffic analysis
Passive network traffic analysis captures and inspects OT protocol traffic without generating any packets that could disrupt sensitive ICS devices.
Question 56: A cybersecurity analyst is asked to produce a 'gap analysis' report for an ICS against IEC 62443. What does this report primarily contain?
- A certification application for IEC 62443 compliance
- A cost estimate for implementing IEC 62443 in full
- A comparison of current ICS security controls against IEC 62443 requirements, identifying deficiencies and remediation priorities (Correct answer)
- A list of all IEC 62443 clauses with no assessment of current state
Correct answer: A comparison of current ICS security controls against IEC 62443 requirements, identifying deficiencies and remediation priorities
A gap analysis compares the current security posture against a standard's requirements and identifies specific shortfalls that must be addressed.
Question 57: When establishing a Security Operations Center (SOC) for ICS monitoring, what is the most important OT-specific capability to include beyond standard IT SOC functions?
- 24/7 staffing with generalist IT security analysts
- Automated blocking of all network traffic flagged as suspicious
- Integration with commercial threat intelligence feeds focused on IT malware
- Understanding of industrial process context to distinguish cyber anomalies from legitimate process variations (Correct answer)
Correct answer: Understanding of industrial process context to distinguish cyber anomalies from legitimate process variations
ICS SOC analysts must understand industrial processes to determine whether an anomaly represents a cyber threat or a legitimate operational event, preventing both missed alerts and false response actions.
Question 58: In an ICS incident response playbook, a 'runbook' is best described as:
- A log of all actions taken during a previous incident
- Step-by-step procedural instructions for responding to a specific incident type (Correct answer)
- A risk register documenting all known vulnerabilities
- A communication plan for notifying stakeholders
Correct answer: Step-by-step procedural instructions for responding to a specific incident type
A runbook contains detailed, step-by-step instructions for responding to a specific type of incident, enabling consistent and efficient response even under pressure.
Question 59: A private security officer at a natural gas compressor station may use deadly force ONLY when:
- The intruder refuses to show identification
- The officer reasonably believes there is an imminent threat of death or serious bodily injury (Correct answer)
- A supervisor authorizes it verbally
- An intruder is spotted inside the outer perimeter fence
Correct answer: The officer reasonably believes there is an imminent threat of death or serious bodily injury
Deadly force is legally justified only when the officer has a reasonable belief of imminent threat of death or serious bodily injury, consistent with state use-of-force statutes.
Question 60: What is a 'data historian' in an ICS environment and why is it a security concern?
- A backup system that archives PLC ladder logic programs
- A time-series database server that stores process data and often bridges IT and OT zones, creating a potential attack pathway (Correct answer)
- A log management system for recording network security events in the OT zone
- A firewall that records all inter-zone communications for forensic analysis
Correct answer: A time-series database server that stores process data and often bridges IT and OT zones, creating a potential attack pathway
A data historian (e.g., OSIsoft PI) stores time-series process data and is frequently connected to both the OT network (to collect data) and the IT network (to share data with business users), making it a potential pivot point for attackers.
Question 61: Which international standard specifically addresses cybersecurity for Industrial Automation and Control Systems (IACS)?
- ISO 9001
- PCI DSS
- IEC 62443 (Correct answer)
- NIST CSF
Correct answer: IEC 62443
IEC 62443 is the international series of standards published by IEC that defines requirements and processes for implementing and maintaining cybersecurity in industrial automation and control systems.
Question 62: What is the significance of 'air-gap jumping' malware (like Stuxnet) in the context of ICS emergency response planning?
- It demonstrates that removable media and supply chain vectors can compromise even physically isolated ICS networks, requiring media controls in response plans (Correct answer)
- It means physical air gaps are no longer needed in ICS networks
- It indicates that only nation-states can attack ICS environments
- It proves that network segmentation is always sufficient for ICS protection
Correct answer: It demonstrates that removable media and supply chain vectors can compromise even physically isolated ICS networks, requiring media controls in response plans
Air-gap jumping malware shows that physically isolated networks can be compromised via USB drives and supply chain, so emergency response plans must account for these vectors.
Question 63: When a conflict arises between IT security policies and OT operational requirements in an ICS environment, which framework is most commonly referenced to find a balanced resolution?
- PCI-DSS
- HIPAA
- ISO 27001 alone
- IEC 62443 (Correct answer)
Correct answer: IEC 62443
IEC 62443 is specifically designed to address cybersecurity in industrial automation and control systems, bridging IT/OT concerns.
Question 64: Which legal concept protects an ICS security vendor from liability when their tools cause unintended disruption during an authorized security assessment?
- Statute of limitations
- Contractual indemnification clause (Correct answer)
- The exclusionary rule
- Sovereign immunity
Correct answer: Contractual indemnification clause
A contractual indemnification clause in the security assessment agreement shifts liability away from the vendor to the contracting organization for authorized activities.
Question 65: Why is staying current with industry developments important for Industrial Control Systems Security professionals?
- Industry changes rarely affect practice
- To provide the best possible service using current knowledge and practices (Correct answer)
- Only academic researchers need to stay current
- It is only important for certification renewal
Correct answer: To provide the best possible service using current knowledge and practices
Staying current ensures professionals provide the best possible service by incorporating the latest knowledge, techniques, and regulatory requirements.
Question 66: An oil refinery conducts a Process Hazard Analysis (PHA). How does PHA relate to an ICS cybersecurity risk assessment?
- PHA focuses exclusively on equipment failure, not cyber threats
- PHA is performed only after a cybersecurity incident occurs
- PHA identifies physical process hazards that cybersecurity attacks could trigger, informing consequence analysis (Correct answer)
- PHA replaces the need for a cybersecurity risk assessment
Correct answer: PHA identifies physical process hazards that cybersecurity attacks could trigger, informing consequence analysis
PHA identifies physical process hazards and their consequences, providing critical input to cybersecurity risk assessments by defining what physical outcomes a successful cyberattack could cause.
Question 67: Which protocol provides secure, encrypted communication for SCADA systems using TLS as a transport-layer security wrapper?
- PROFIBUS DP
- Modbus RTU
- OPC DA
- OPC UA (Correct answer)
Correct answer: OPC UA
OPC UA natively supports TLS encryption and certificate-based authentication for secure machine-to-machine communication.
Question 68: What is the most important principle in professional Industrial Control Systems Security practice?
- Following only personal judgment
- Maximizing revenue from each client
- Working as quickly as possible
- Maintaining competence through continuous learning and adherence to standards (Correct answer)
Correct answer: Maintaining competence through continuous learning and adherence to standards
Maintaining competence through continuous learning and adherence to professional standards ensures quality service delivery and public protection in Industrial Control Systems Security practice.
Question 69: Which element MUST appear in every ICS security report to ensure traceability?
- All raw packet captures from network scans
- A full source code listing of all tested applications
- Report version number, date, author, and approval signatures (Correct answer)
- Photographs of every physical device inspected
Correct answer: Report version number, date, author, and approval signatures
Version, date, authorship, and approval signatures establish traceability and accountability for every formal security report.
Question 70: What is the principle of least privilege?
- Removing all access until requested
- Giving all users administrator access for convenience
- Granting users only the minimum access necessary to perform their duties (Correct answer)
- Restricting access only for external users
Correct answer: Granting users only the minimum access necessary to perform their duties
The principle of least privilege limits access to the minimum necessary for job functions, reducing the attack surface and potential impact of compromised accounts.
Question 71: What is the key difference between a vulnerability report and a penetration test report in the ICS context?
- Vulnerability reports are longer than penetration test reports
- Vulnerability reports identify weaknesses without exploitation; penetration test reports document successful exploitation attempts and their impact (Correct answer)
- Vulnerability reports are always classified; penetration test reports are always public
- Penetration test reports are only for IT systems, not ICS
Correct answer: Vulnerability reports identify weaknesses without exploitation; penetration test reports document successful exploitation attempts and their impact
Vulnerability reports catalog identified weaknesses, while penetration test reports describe how vulnerabilities were exploited to demonstrate real-world impact.
Question 72: A risk treatment option where an organization accepts the potential loss from a risk without taking action is called:
- Risk avoidance
- Risk transfer
- Risk mitigation
- Risk acceptance (Correct answer)
Correct answer: Risk acceptance
Risk acceptance (also called risk retention) means the organization acknowledges the risk and decides not to take additional action, often because the cost of mitigation exceeds the potential loss.
Question 73: How soon after a service or session should documentation be completed?
- At the end of the month
- As soon as possible, ideally within 24 hours (Correct answer)
- Only when an audit is scheduled
- Within one week
Correct answer: As soon as possible, ideally within 24 hours
Prompt documentation, ideally within 24 hours, ensures accuracy of recorded information and meets professional and legal standards.
Question 74: Which wireless protocol is commonly used in industrial environments for low-power sensor networks but has known security vulnerabilities?
- LTE Cat-M1
- WirelessHART
- Zigbee (802.15.4) (Correct answer)
- Wi-Fi 6 (802.11ax)
Correct answer: Zigbee (802.15.4)
Zigbee (IEEE 802.15.4) is widely used for industrial sensor networks but has documented vulnerabilities including key extraction weaknesses.
Question 75: In the context of ICS risk management, 'inherent risk' is best defined as:
- The raw risk level that exists before any controls or mitigations are applied (Correct answer)
- The risk level after all security controls have been fully implemented
- The risk accepted by senior management after reviewing the risk register
- The risk transferred to third parties through contracts or insurance
Correct answer: The raw risk level that exists before any controls or mitigations are applied
Inherent risk represents the natural exposure to a threat before any security controls are applied, establishing the baseline for risk treatment decisions.
Question 76: An operator notices that a flow meter reading in the SCADA HMI has been constant for 6 hours without variation. What security concern should this raise?
- The historian is compressing redundant data
- The HMI display needs to be refreshed
- A sensor or its data feed may have been spoofed or frozen by an attacker (Correct answer)
- The process has reached a stable steady state
Correct answer: A sensor or its data feed may have been spoofed or frozen by an attacker
A perfectly flat reading over an extended period is a hallmark indicator of sensor spoofing or data substitution attacks targeting ICS monitoring.
EC-Council ICS/SCADA Cybersecurity Certification
The EC-Council ICS/SCADA Cybersecurity certification validates professionals' ability to defend industrial control systems against cyber threats, covering network defense, TCP/IP fundamentals, vulnerability management, security standards, and intrusion detection for OT/ICS environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds