Free ICS-SCADA sample questions
Real questions from the ICS / SCADA Security practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
During a network packet capture analysis of a SCADA system that monitors a remote pipeline, an analyst observes a TCP packet with both the SYN and FIN flags set. The packet is directed at the Human Machine Interface (HMI) server. What type of network scan is this packet indicative of?
A penetration tester is tasked with identifying live hosts and open Modbus TCP ports (502) on a Level 1 network segment of a manufacturing plant. The tester is concerned that a standard Nmap SYN scan (`-sS`) might disrupt sensitive PLCs. Which Nmap scan technique is considered the safest alternative for this environment, minimizing the risk of causing a denial-of-service condition on legacy devices?
A vulnerability assessment of a building automation system reveals a critical vulnerability in a BACnet-enabled HVAC controller. The CVSS v3.1 base score is calculated as 9.8. The vendor has released a patch, but it has not been tested by the facility's OT team. The security manager needs to communicate the current risk level to stakeholders. Which CVSS metric group should be used to reflect the availability of a patch and the current exploitability of the vulnerability?
True or False: According to NIST SP 800-82, the primary security objective for most Industrial Control Systems (ICS) is confidentiality, followed by integrity and availability, which is the same priority as in traditional IT systems.
A security architect is designing a network for a new chemical processing plant and must adhere to the Purdue Model and IEC 62443 standards. The design requires a secure method for transferring historical process data from the plant's historian server at Level 3 to the enterprise business network at Level 4. Which of the following solutions provides the highest level of security for this data transfer by enforcing a one-way communication flow?
A water treatment facility has recently connected its control network to the corporate network to allow for business analytics. The security team wants to monitor the control network for malicious activity without installing agents on the sensitive PLCs and HMIs. They have implemented a SPAN port on a core switch in the control network. Which type of security tool would be most effective when connected to this SPAN port for detecting threats specific to ICS protocols like DNP3 and Modbus?
An incident response team is analyzing a compromise of a substation's engineering workstation. The attacker used a sophisticated piece of malware that first gathered information about the connected Schneider Electric PLCs, then modified their logic to cause a targeted outage. The team is mapping the attacker's actions to the MITRE ATT&CK for ICS framework. Which of the following activities represent tactics from this framework? (Select TWO)
A railway signaling system uses a legacy SCADA application that communicates with RTUs over serial connections via terminal servers. A security audit found that the application authenticates users against a local password file with weak, unsalted MD5 hashes. The vendor states that the application cannot be updated. What is the most effective compensating control to mitigate the risk of password cracking?
An OT administrator is using Wireshark to troubleshoot a communication issue between an HMI and a PLC using Modbus TCP. The administrator applies the display filter `modbus.func_code == 16`. What specific Modbus operation is the administrator trying to isolate?
10 more free samples are waiting
Create a free account to unlock the whole ICS-SCADA sample bank, or get full access to all 256 practice questions in the simulator.