EC-COUNCIL · ICS/SCADA Cybersecurity

EC-Council ICS/SCADA Cybersecurity Exam Practice Questions

75 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 75 questions in this pack

Question 1

What type of communication protocol does Modbus RTU use?

  1. UDP
  2. ICMP
  3. Serial
  4. SSTP
Show answer and explanation

Correct answer: C. Serial

Modbus RTU (Remote Terminal Unit) is a serial communication protocol that operates over RS-232 or RS-485 serial connections. It uses a master-slave architecture and transmits data in binary format over serial lines, making serial communication the defining characteristic of Modbus RTU.

Why the other options are wrong

  • A. UDP is a network layer protocol used for IP-based communications, not serial protocols like Modbus RTU.
  • B. ICMP is an Internet Control Message Protocol used for network diagnostics, not for industrial device communication.
  • D. SSTP is a VPN tunneling protocol, completely unrelated to Modbus communication standards.

Question 2

Which of the ICS/SCADA generations is considered monolithic?

  1. Second
  2. First
  3. Fourth
  4. Third
Show answer and explanation

Correct answer: B. First

The first generation of ICS/SCADA systems is characterized as monolithic, consisting of standalone, integrated systems with proprietary hardware and software that performed all control functions within a single unit without network connectivity.

Why the other options are wrong

  • A. The second generation introduced distributed control systems (DCS) with networked components, moving away from monolithic architecture.
  • C. The third generation brought SCADA systems with more open standards and remote access capabilities.
  • D. The fourth generation represents modern ICS with cloud integration and advanced cybersecurity considerations.

Question 3

Which of the following components is not part of the Authentication Header (AH)?

  1. Replay
  2. Authentication
  3. Confidentiality
  4. Integrity
Show answer and explanation

Correct answer: C. Confidentiality

The Authentication Header (AH) in IPsec provides authentication, integrity, and replay protection for IP packets, but does not provide confidentiality. Confidentiality (encryption) is provided by the Encapsulating Security Payload (ESP) component of IPsec, not by AH.

Why the other options are wrong

  • A. Replay protection is a core function of AH, which uses sequence numbers to prevent replay attacks.
  • B. Authentication is the primary function of the Authentication Header.
  • D. Integrity verification is a fundamental capability of AH, ensuring data has not been altered in transit.

See all 10 free questions Get the full pack, US$39

75 practice questions for EC-Council ICS/SCADA Cybersecurity certification, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 75 questions mapped to the ICS/SCADA Cybersecurity course modules
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

An ICS/SCADA Cybersecurity attempt costs US$250. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 75 questions

What makes the ICS/SCADA Cybersecurity exam hard

The EC-Council ICS/SCADA Cybersecurity exam is an OT security exam written for IT security people, and that is the angle most of the questions take: how is an industrial network different, why does the usual IT answer break a plant, and what should be done instead. It is 75 questions in two hours with a 70% pass mark, and a lot of the marks come from knowing the protocols and the incidents by name.

The course modules drive the blueprint: ICS and SCADA network defence fundamentals covering PLCs, RTUs, HMIs and the Purdue model, TCP/IP review, the hacking methodology applied to industrial environments, vulnerability management with ICS-CERT advisories, standards including IEC 62443, NIST SP 800-82 and NERC CIP, securing the ICS network with segmentation and protocol-aware firewalls, and bridging the air gap with intrusion detection.

Expect questions on Stuxnet, BlackEnergy, Industroyer, TRITON and Pipedream and what each targeted, because the incidents are the case studies the exam uses.

About the exam

The EC-Council ICS/SCADA Cybersecurity certification covers ICS and SCADA network defence, TCP/IP fundamentals, the hacking methodology applied to industrial systems, vulnerability management, standards and regulations, securing ICS networks, bridging the air gap, and intrusion detection in OT environments. The prerequisite is basic networking and security knowledge; EC-Council recommends its ICS/SCADA course.

Exam topics

  • Introduction to ICS/SCADA network defence
  • TCP/IP fundamentals for ICS environments
  • Introduction to hacking and the attack methodology
  • Vulnerability management
  • Standards and regulations for cybersecurity (IEC 62443, NIST SP 800-82, NERC CIP)
  • Securing the ICS network
  • Bridging the air gap
  • Introduction to intrusion detection systems

75 multiple choice questions, 120 minutes, passing score 70%, US$250 per attempt, ECC Exam Center with remote proctoring, certification valid for three years with EC-Council continuing education.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the EC-Council ICS/SCADA Cybersecurity pack?

75 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.