ICS-SCADA Sample Questions

ICS-SCADA Sample Questions & Answers

ICS/SCADA defense fundamentals, core hacking concepts, and securing ICS protocols with IPsec share the heaviest weighting, next to TCP/IP basics, vulnerability management, cybersecurity standards, bridging the air gap, and intrusion detection systems.

Launch the full ICS-SCADA simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Securing the ICS/SCADA Network · Isolating Networks

    A security architect is designing a network for a new chemical processing plant and must adhere to the Purdue Model and IEC 62443 standards. The design requires a secure method for transferring historical process data from the plant's historian server at Level 3 to the enterprise business network at Level 4. Which of the following solutions provides the highest level of security for this data transfer by enforcing a one-way communication flow?

    Show answer & explanation

    Correct answer: D

    A data diode is a hardware device that physically enforces a one-way data flow, making it impossible for traffic to travel from the less secure enterprise network back into the more secure control network. This provides the highest level of segmentation and security against threats originating from the IT side. While a firewall, jump server, or mirrored servers in a DMZ provide good security, they are software-based controls that can still be misconfigured or compromised, potentially allowing two-way traffic. The data diode offers a physically guaranteed unidirectional path.

  2. Question 2Intermediate

    Bridging the Air Gap · ICS Monitoring

    A water treatment facility has recently connected its control network to the corporate network to allow for business analytics. The security team wants to monitor the control network for malicious activity without installing agents on the sensitive PLCs and HMIs. They have implemented a SPAN port on a core switch in the control network. Which type of security tool would be most effective when connected to this SPAN port for detecting threats specific to ICS protocols like DNP3 and Modbus?

    Show answer & explanation

    Correct answer: C

    An ICS-aware Network Security Monitoring (NSM) platform is specifically designed to passively monitor and analyze industrial network traffic. It uses deep packet inspection (DPI) to understand protocols like DNP3 and Modbus, allowing it to detect anomalous or malicious commands, such as unauthorized stop commands or firmware updates. A traditional IT NIDS lacks this protocol-specific knowledge. A HIDS only protects the host it's on and doesn't provide network-wide visibility. A SIEM requires log sources and doesn't directly analyze packet captures from a SPAN port for this purpose.

  3. Question 3AdvancedSelect 2

    Introduction to Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) · MITRE ATT&CK Matrix

    An incident response team is analyzing a compromise of a substation's engineering workstation. The attacker used a sophisticated piece of malware that first gathered information about the connected Schneider Electric PLCs, then modified their logic to cause a targeted outage. The team is mapping the attacker's actions to the MITRE ATT&CK for ICS framework. Which of the following activities represent tactics from this framework? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

  4. Question 4Intermediate

    Introduction to ICS/SCADA Network Defense · Risk Management

    A railway signaling system uses a legacy SCADA application that communicates with RTUs over serial connections via terminal servers. A security audit found that the application authenticates users against a local password file with weak, unsalted MD5 hashes. The vendor states that the application cannot be updated. What is the most effective compensating control to mitigate the risk of password cracking?

    Show answer & explanation

    Correct answer: B

    Since the underlying vulnerability (weak hashing) cannot be fixed, the most effective compensating control is to prevent unauthorized access to the server and the password file itself. Strict network segmentation, using firewalls to create a secure enclave around the SCADA server, and limiting access to only a few hardened operator workstations dramatically reduces the attack surface. This prevents an attacker from ever reaching the server to obtain the password file. While password policies are good practice, they don't fix the weak hashing, which allows even complex passwords to be cracked quickly if the hash file is stolen.

  5. Question 5Beginner

    TCP/IP 101 · ICS/SCADA Protocols

    An OT administrator is using Wireshark to troubleshoot a communication issue between an HMI and a PLC using Modbus TCP. The administrator applies the display filter modbus.func_code == 16. What specific Modbus operation is the administrator trying to isolate?

    Show answer & explanation

    Correct answer: C

    In the Modbus protocol, function codes define the action to be performed. Function code 16 (decimal) corresponds to the 'Write Multiple Registers' command. This command is used to write a block of contiguous holding registers in a remote device. This is a common operation for sending a set of new parameters or setpoints to a PLC.

  6. Question 6Advanced

    Introduction to Hacking · Enumeration

    A red teamer has gained access to an engineering workstation inside a substation automation network that uses the IEC 61850 protocol. The red teamer wants to discover the data models of the Intelligent Electronic Devices (IEDs) on the network. Which protocol, commonly used within the IEC 61850 suite for this purpose, should the red teamer attempt to use for enumeration?

    Show answer & explanation

    Correct answer: D

    Within the IEC 61850 standard, MMS is the client-server protocol used for a variety of functions, including reporting, control, and crucially, discovering the data model and reading/writing data points on an IED. An attacker would use MMS to enumerate the logical nodes, data objects, and data attributes of the IEDs to understand the process and plan further attacks. GOOSE and SV are typically used for high-speed peer-to-peer messaging and are not suitable for enumeration.

  7. Question 7Intermediate

    Vulnerability Management · Metasploit and Bacnet

    A security consultant is using the Metasploit Framework to test the security of a building management system that uses BACnet/IP. The consultant wants to identify writable properties on a specific BACnet device. Which Metasploit module would be most appropriate for this task?

    Show answer & explanation

    Correct answer: B

    Metasploit auxiliary modules are used for reconnaissance, scanning, and enumeration rather than direct exploitation. The auxiliary/scanner/bacnet/discover_properties module is specifically designed to query a BACnet device and enumerate its objects and properties, including identifying which ones are writable. This is a critical step in a penetration test to find points that can be manipulated.

  8. Question 8Intermediate

    Standards and Regulation for Cybersecurity · CFATS

    A critical infrastructure facility is required to comply with the Chemical Facility Anti-Terrorism Standards (CFATS). Which of the following is a key requirement under the CFATS Risk-Based Performance Standards (RBPS) that directly relates to cybersecurity of the facility's ICS?

    Show answer & explanation

    Correct answer: C

    CFATS is a set of performance-based standards, meaning it dictates the required security outcomes rather than specific technologies. RBPS 8 - Cyber directly requires high-risk chemical facilities to implement measures to secure their critical cyber assets. This includes preventing unauthorized access, detecting intrusions, and delaying the ability of an attacker to cause harm, as well as securing any connections between the ICS and business networks.

  9. Question 9Intermediate

    Securing the ICS/SCADA Network · IPsec Modes

    An OT engineer needs to configure an IPsec VPN between a remote RTU site and the central control center. The goal is to encrypt the entire original IP packet (including the original IP header) and add a new IP header for routing over the public internet. Which IPsec mode and protocol combination should be used?

    Show answer & explanation

    Correct answer: C

    IPsec Tunnel Mode is used to create a secure VPN between two networks (site-to-site). It encapsulates the entire original IP packet, encrypts it, and adds a new IP header for routing. The Encapsulating Security Payload (ESP) protocol provides confidentiality (encryption) and integrity. Transport mode only encrypts the payload, leaving the original header intact, which is not suitable for this scenario. Authentication Header (AH) provides integrity but not encryption.

  10. Question 10IntermediateSelect 3

    Bridging the Air Gap · SIEM

    A security operations center (SOC) for a large utility company is implementing a SIEM. To detect potentially malicious activity, the analysts need to write correlation rules that trigger an alert if an operator workstation in the corporate network (10.10.0.0/16) attempts to communicate directly with a PLC on the process control network (172.16.1.0/24). According to the Purdue Model, this traffic is a violation of network segmentation. Which of the following components are essential for the SIEM to detect this activity? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, D

Ready for the real thing?

The full ICS-SCADA simulator has every exam-style question, timed mode, and instant scoring.