EC-Council · ICS-SCADA
Validates the ability to secure industrial control systems and SCADA networks, covering ICS/SCADA network defense, vulnerability assessment, risk analysis for IT and OT environments, intrusion detection, ICS-specific standards and regulations, and incident response for critical infrastructure.
Practice Questions
627
≈ 5 practice exams
Duration
120 minutes
Passing Score
70%
Difficulty
SpecialtyLast Updated
Sep 2026
This practice exam follows the official EC-Council ICS/SCADA Cybersecurity exam blueprint, which splits the marks across eight domains. Three carry 16 percent each: introduction to ICS/SCADA network defense, introduction to hacking, and securing the ICS/SCADA network. TCP/IP 101 adds 14 percent, so those four areas decide 62 percent of your score. The rest covers vulnerability management (13 percent), intrusion detection and prevention systems (13 percent), standards and regulation for cybersecurity (6 percent), and bridging the air gap (6 percent). This 627-question bank is built to match that split, so the heavyweight defense and hacking-methodology domains get real depth.
On exam day you face 75 multiple choice questions in 2 hours, with a 70 percent passing score listed on the official exam page. Delivery runs through EC-Council's own exam portal (the ECC Exam Center) with remote proctoring. The blueprint names OT specifics a general security cert never touches, and this bank drills them: Modbus, BACnet, and Siemens protocol behavior, the Conpot ICS honeypot, Metasploit modules against Modbus and BACnet targets, IPsec modes for securing ICS protocols, CVSS scoring, and the MITRE ATT&CK matrix applied to ICS malware. The standards domain is only 6 percent but names its sources outright: ISO 27001, CFATS, IEC 62443, and NIST SP 800-82.
Eligibility runs two ways: complete official EC-Council training, or apply as a self-study candidate with at least 1 year of information security work experience plus a non-refundable $100 application fee. The exam voucher costs $699 ($450 for a retake) and the certification stays valid for 3 years, renewed with 120 ECE credits and an annual EC-Council CE fee. Start with the 30 free questions, then work through the full 627-question bank until your accuracy holds steady across all eight domains, especially the three 16 percent domains where nearly half the marks sit.
The EC-Council ICS/SCADA Cybersecurity certification validates a professional's ability to defend Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) networks against cyber threats. The certification covers the full spectrum of OT/IT security—from foundational TCP/IP networking and ICS-specific protocols to advanced topics such as vulnerability management, intrusion detection, digital forensics, and incident response tailored to critical infrastructure environments. Candidates learn to analyze risk across both IT corporate networks and operational technology (OT) environments, with particular focus on the unique architectural and protocol challenges that distinguish ICS/SCADA systems from traditional enterprise IT.
The certification addresses the growing threat landscape targeting critical infrastructure, including documented malware such as Stuxnet and Triton/TRISIS that can cause physical disruption to industrial processes. It bridges the security gap between IT and OT environments by providing defenders with attacker-perspective methodologies—scanning, footprinting, enumeration, and exploitation techniques—so that practitioners can better anticipate and counter adversary tactics against pipelines, energy grids, water treatment facilities, and manufacturing systems.
This certification is designed for IT and OT professionals who administer, patch, or secure ICS and SCADA systems, including System Administrators and System Engineers working in industrial environments such as oil and gas, energy, utilities, and manufacturing. Security Consultants who conduct security assessments of ICS/SCADA installations are also a primary audience, as are Business Systems Analysts who support interfaces between corporate business systems and SCADA networks.
The credential is appropriate for mid-career professionals with a networking and security background who are transitioning into or expanding responsibilities within operational technology environments. It suits those who need a foundational-to-intermediate understanding of ICS/SCADA-specific threats, standards, and defensive strategies, and who are responsible for establishing or maintaining information security policies for critical infrastructure.
There are no mandatory formal prerequisites published by EC-Council for this exam, but candidates are strongly recommended to have Linux operating system fundamentals including basic command-line usage before attempting the course or exam. A solid grasp of essential networking concepts is expected—specifically the OSI model, TCP/IP protocol architecture, networking devices, and transmission media. Familiarity with network traffic inspection tools such as Wireshark, TShark, or TCPdump is also recommended, as is conceptual knowledge of programming or scripting.
Candidates should additionally possess a working understanding of basic cybersecurity concepts including malware categories, intrusion detection systems, firewalls, and common vulnerabilities. Prior exposure to IT security operations or a general security certification (such as CompTIA Security+) would be beneficial, though not required. Minors seeking to sit the exam must provide written parental consent along with institutional documentation per EC-Council policy.
The ICS-SCADA exam consists of 75 multiple-choice questions and must be completed within a 2-hour (120-minute) time limit. The passing score is 70%. The exam is delivered through EC-Council's ECC Exam Center, which provides proctored testing in a controlled environment. Question types are multiple-choice with a single correct answer, testing both conceptual knowledge and applied understanding of ICS/SCADA security principles.
EC-Council publishes an official Exam Blueprint document (available at cert.eccouncil.org) that outlines the topic domains and their respective weightings, which candidates are advised to use as a primary study guide. There are no publicly disclosed unscored or beta questions built into the exam format at this time.
Professionals holding the EC-Council ICS/SCADA Cybersecurity certification are positioned for roles such as ICS/SCADA Security Analyst, OT Security Engineer, Critical Infrastructure Security Consultant, and Industrial Cybersecurity Specialist. These roles exist across high-demand sectors including energy and utilities, oil and gas, water and wastewater, manufacturing, and transportation—all of which face increasing regulatory pressure and threat actor attention. The ICS/SCADA security skills market remains undersupplied relative to demand, with practitioners who can bridge IT and OT security commanding premium compensation, typically in the range of $90,000–$140,000+ USD annually depending on sector and geography.
The EC-Council ICS-SCADA credential serves as a solid entry point into OT cybersecurity and complements other certifications such as GICSP (Global Industrial Cyber Security Professional by GIAC) or ISA/IEC 62443 Cybersecurity certificates. While GICSP is more widely recognized at the senior level, the EC-Council certification offers a more accessible path for professionals transitioning from general IT security into the industrial domain, and is particularly useful for those already embedded in EC-Council's certification ecosystem (CEH, CPENT, CHFI).
5 sample questions with answers and explanations. The full bank has 627 questions, enough for 5 full-length practice exams.
Preview — answers shown1. A SCADA administrator needs to monitor DNP3 communications between a master station and remote RTUs for suspicious activity. On which port should the network monitoring system capture DNP3 traffic? (Select one!)
Explanation
DNP3 (Distributed Network Protocol 3) operates on TCP/UDP port 20000 for communications between SCADA masters and outstations/RTUs. DNP3 can run over either TCP for reliable delivery or UDP for lower overhead in stable networks. TCP port 502 is used by Modbus TCP, not DNP3. TCP port 102 is used by Siemens S7comm protocol. UDP port 47808 is used by BACnet building automation protocol. Understanding protocol-to-port mappings is essential for properly configuring firewalls, intrusion detection systems, and network monitoring tools in SCADA environments.
2. A power utility is implementing IEC 60870-5-104 for remote substation communication. The security team wants to enable TLS encryption for this protocol. Which port should they configure for TLS-secured IEC-104 traffic? (Select one!)
Explanation
IEC 60870-5-104 uses TCP port 2404 for standard unencrypted communication, but when TLS encryption is enabled, the protocol uses TCP port 19998. This port separation allows clear distinction between encrypted and unencrypted traffic and prevents downgrade attacks. TCP port 102 is used by Siemens S7comm protocol. UDP port 20000 is used by DNP3. Organizations implementing IEC-104 should migrate to the TLS-secured port 19998 to protect SCADA communications from eavesdropping and tampering, especially when communicating over untrusted networks.
3. A utility company monitors IEC 60870-5-104 communications between SCADA master and substation RTUs. The security team configures Wireshark to analyze control commands. Which TCP port should be monitored for IEC-104 traffic? (Select one!)
Explanation
IEC 60870-5-104 protocol operates on TCP port 2404 for standard communications. When TLS encryption is implemented, IEC-104 uses port 19998. TCP port 102 is used by Siemens S7comm protocol for PLC communications. TCP port 502 is the standard port for Modbus TCP protocol. TCP port 20000 is used by DNP3 protocol for both TCP and UDP communications in utility networks. Each industrial protocol has designated port numbers that must be understood for proper network monitoring, firewall configuration, and security analysis of SCADA systems.
4. A chemical plant is implementing BACnet for building automation and HVAC control. The network administrator needs to configure firewall rules to allow BACnet device discovery traffic. Which protocol and port must be permitted? (Select one!)
Explanation
BACnet operates on UDP port 47808 for building automation communication including Who-Is and I-Am device discovery messages. BACnet uses UDP rather than TCP because building automation requires broadcast and multicast capabilities for device discovery across network segments. TCP port 47808 is not used by BACnet as the protocol relies on connectionless UDP communication. TCP port 502 is for Modbus TCP. UDP port 2222 is for EtherNet/IP implicit messaging and real-time I/O data.
5. A manufacturing facility security team is investigating potential reconnaissance activity targeting their Allen-Bradley ControlLogix PLCs. Nmap scan logs show connection attempts to TCP port 44818. Which ICS protocol is being enumerated? (Select one!)
Explanation
TCP port 44818 is the designated port for EtherNet/IP explicit messaging, which is part of the Common Industrial Protocol (CIP) used by Allen-Bradley and Rockwell Automation devices. Explicit messaging handles configuration, diagnostics, and request-response communications. Modbus TCP uses port 502. Siemens S7comm uses port 102. DNP3 uses port 20000. Port 44818 is specifically associated with Allen-Bradley devices and EtherNet/IP protocol.
75 multiple-choice questions with a 2-hour (120-minute) time limit, delivered through EC-Council's own exam portal (the ECC Exam Center) with remote proctoring.
70 percent. EC-Council lists the passing score on the official certification page at cert.eccouncil.org alongside the 75-question count and 2-hour duration.
The exam voucher is $699 and a retake voucher is $450 on the EC-Council store. All candidates also pay a $100 non-refundable eligibility application fee, which is included in the training fee if you take official training. Vouchers are valid for 1 year.
Eight weighted domains: introduction to ICS/SCADA network defense (16%), introduction to hacking (16%), securing the ICS/SCADA network (16%), TCP/IP 101 (14%), vulnerability management (13%), intrusion detection and prevention systems (13%), standards and regulation for cybersecurity (6%), and bridging the air gap (6%).
You need either official EC-Council training or, for self-study candidates, at least 1 year of verified information security work experience. EC-Council also recommends Linux command-line fundamentals, solid TCP/IP networking, basic scripting concepts, and familiarity with Wireshark, TShark, or TCPdump.
Yes. It is valid for 3 years. To renew, you earn 120 ECE (continuing education) credits within the 3-year window and pay EC-Council's annual continuing education fee ($80 per year for most of its certifications).
EC-Council targets four groups: IT professionals who set information security policy, SCADA systems personnel and business system analysts who support SCADA interfaces, system administrators and engineers who patch or secure ICS/SCADA, and security consultants who assess SCADA or ICS environments.
EC-Council Certified Incident Handler (ECIH)
ECIH · 590 questions
EC-Council Certified Encryption Specialist (ECES)
ECES · 627 questions
Ethical Hacking Essentials (EHE)
EHE · 627 questions
Certified Application Security Engineer Java (CASE-Java)
CASE-Java · 623 questions
Network Defense Essentials (NDE)
NDE · 627 questions
Certified Secure Computer User (CSCU)
CSCU · 630 questions
$17.99
One-time access to this exam