Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which of the IEC 62443 Security Levels is identified by a cybercrime/hacker target?
IEC 62443 is an international series of standards on Industrial communication networks and system security, specifically related to Industrial Automation and Control Systems (IACS). Within the IEC 62443 standards, Security Level 3 is defined as protection against deliberate or specialized intrusion. It is designed to safeguard against threats from skilled attackers (cybercriminals or hackers) targeting specific processes or operations within the industrial control system. Reference:
International Electrotechnical Commission, 'IEC 62443 Standards'.
Which of the CVSS metrics refer to the exploit quotient of the vulnerability?
The Common Vulnerability Scoring System (CVSS) uses several metrics to assess the severity of vulnerabilities. Among them, the Temporal metric group specifically reflects the exploit quotient of a vulnerability.
Temporal metrics consider factors that change over time after a vulnerability is initially assessed. These include:
Exploit Code Maturity: This assesses the likelihood of the vulnerability being exploited based on the availability and maturity of exploit code.
Remediation Level: The level of remediation available for the vulnerability, which influences the ease of mitigation.
Report Confidence: This metric measures the reliability of the reports about the vulnerability.
These temporal factors directly affect the exploitability and potential threat posed by a vulnerability, adjusting the base score to provide a more current view of the risk.
Reference
Common Vulnerability Scoring System v3.1: User Guide.
'Understanding CVSS,' by FIRST (Forum of Incident Response and Security Teams).
Which component of the IT Security Model is the highest priority in ICS/SCADA Security?
In ICS/SCADA systems, the highest priority typically is Availability, due to the critical nature of the services and infrastructures they support. These systems often control vital processes in industries like energy, water treatment, and manufacturing. Any downtime can lead to significant disruptions, safety hazards, or economic losses. Thus, ensuring that systems are operational and accessible is a primary security focus in the context of ICS/SCADA security. Reference:
National Institute of Standards and Technology (NIST), 'Guide to Industrial Control Systems (ICS) Security'.
Which of the following is NOT an exploit tool?
Among the options listed, Nessus is primarily a vulnerability assessment tool, not an exploit tool. It is used to scan systems, networks, and applications to identify vulnerabilities but does not exploit them. On the other hand, Canvas, Core Impact, and Metasploit are exploit tools designed to actually perform attacks (safely and legally) to demonstrate the impact of vulnerabilities. Reference:
Tenable, Inc., 'Nessus FAQs'.
What is the size of the AH in bits with respect to width?
The Authentication Header (AH) in the context of IPsec has a fixed header portion of 24 bits and a mutable part that can vary, but when considering the fixed structure of the AH itself, the width is typically considered to be 32 bits at its core structure for basic operations in providing integrity and authentication, without confidentiality. Reference:
RFC 4302, 'IP Authentication Header'.
75 questions covering all exam domains, starting from $20
Exam domains verified against: Official Eccouncil ICS-SCADA exam guide, last checked September 2026.
Learn the IT versus ICS/SCADA security models, including typical threat vectors and attack surfaces specific to industrial control systems. Study the differences between traditional IT protocols and ICS protocols like Modbus and BACnet, then understand how to identify assets, characterize systems, and model threats using frameworks like SCADA security architecture.
Sample question from this domain above: Q2
Master the encapsulation and de-encapsulation of data across the TCP/IP stack, covering IPv4, UDP, and TCP protocols. Explore how ICS-specific protocols operate within TCP/IP architecture and the unique networking challenges that arise when applying traditional network theory to industrial environments.
Study the goals and objectives of attackers, common attack types, and ethical hacking methodologies. Learn footprinting and reconnaissance techniques, then understand how to analyze attacker behavior and testing approaches that are relevant to defending ICS/SCADA systems.
Understand vulnerability scanning tools and evaluation methods specific to ICS/SCADA environments. Learn how Metasploit applies to industrial systems and the unique challenges of identifying and assessing vulnerabilities in operational technology versus traditional IT.
Sample question from this domain above: Q4
Understand compliance frameworks and regulatory requirements including ISO 27001, IEC 62443, CFATS, and NIST SP 800-82. Know which standards apply to different industrial sectors and how regulatory bodies like NERC CIP enforce security requirements for critical infrastructure.
Learn how to secure industrial protocols and implement network segmentation. Study IPsec deployment modes and firewall configuration techniques designed specifically for OT environments where availability cannot be compromised for security.
Sample question from this domain above: Q1
Study methods for secure ICS/SCADA connections and network segmentation strategies. Learn how next-generation firewalls and monitoring systems create controlled zones and detect anomalies in operational technology networks without disrupting critical processes.
Understand the purpose and architecture of IDS and IPS systems deployed in ICS/SCADA networks. Learn how to interpret intrusion analysis, recognize signs of compromise, and respond to security incidents in environments where downtime has serious safety implications.
Common questions about the exam itself