Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by EC-Council
Exam Format
Registration
Validity
ICS-SCADA Exam Topics and Domains
ICS-SCADA is organized into 8 weighted domains. Expect to work with BACnet tools, IDS platforms, Metasploit modules, Nessus, and more.
Introduction to ICS/SCADA Network Defense
Typical Security Model
- Understand typical security models for ICS/SCADA
- Identify security architecture components
ICS/SCADA Overview
- Describe ICS/SCADA components and architecture
- Understand differences between ICS and traditional IT systems
Risk Management
- Perform risk assessments for ICS/SCADA environments
- Apply risk management frameworks
Security Policy
- Develop security policies for ICS/SCADA
- Implement policy enforcement mechanisms
ICS/SCADA Attacks
- Identify common ICS/SCADA attack vectors
- Analyze real-world ICS/SCADA attacks
Attack Surface
- Map ICS/SCADA attack surfaces
- Implement attack surface reduction techniques
Protocols and Siemens
- Understand Siemens industrial protocols
- Identify protocol-specific vulnerabilities
Modbus and BACnet
- Analyze Modbus and BACnet security
- Implement protocol-specific protections
Challenges with ICS/SCADA Risk
- Identify unique ICS/SCADA risk challenges
- Develop risk mitigation strategies
Asset Identification and System Characterization
- Perform asset identification and inventory
- Characterize ICS/SCADA systems
Vulnerability Identification and Threat Modelling
- Identify ICS/SCADA vulnerabilities
- Create threat models for industrial systems
SCADA Framework
- Understand SCADA frameworks
- Implement secure SCADA architectures
IT and ICS Comparison
- Compare IT and ICS security requirements
- Address IT/OT convergence challenges
Standards
- Understand ICS/SCADA security standards
- Apply standards to industrial environments
TCP/IP 101
Encapsulation and De-encapsulation
- Understand network encapsulation
- Analyze protocol data units
TCP/IP
- Master TCP/IP fundamentals
- Identify TCP/IP security issues
IPv4, UDP, TCP Header
- Analyze protocol headers
- Identify header-based attacks
Threat Containment
- Implement threat containment
- Design network isolation strategies
Network Protocols
- Analyze network protocol security
- Implement protocol protections
ICS/SCADA Protocols
- Understand ICS/SCADA protocols
- Identify protocol-specific risks
Introduction to Hacking
Motives, Goals, and Objectives of Information Security Attacks
- Understand attacker motivations
- Profile threat actors
Hacking and Ethical Hacking
- Apply ethical hacking principles
- Understand legal frameworks
Mindset of the Attacker
- Think like an attacker
- Anticipate attack strategies
Types of Testing
- Select appropriate testing methods
- Execute various testing types
Hacking Methodology
- Apply hacking methodology
- Execute attack lifecycle phases
Footprinting
- Perform footprinting activities
- Gather target intelligence
Scanning
- Execute network scanning
- Interpret scan results
Enumeration
- Perform service enumeration
- Extract detailed information
Vulnerability Research
- Research vulnerabilities
- Validate exploits
Exploration
- Explore compromised systems
- Maintain persistence
Common ICS Architectures
- Analyze ICS architectures
- Identify architectural weaknesses
Modems and Wardialing
- Identify modem vulnerabilities
- Perform wardialing attacks
Penetration Testing
- Execute penetration tests
- Document findings
ICS/SCADA Testing
- Perform safe ICS testing
- Minimize operational impact
Vulnerability Management
Defining Vulnerability
- Define vulnerabilities
- Classify vulnerability types
Vulnerability Scanners
- Configure vulnerability scanners
- Interpret scan results
Vulnerability Assessment
- Conduct vulnerability assessments
- Validate findings
Malware Ecosystem
- Analyze ICS malware
- Understand malware ecosystem
Vulnerability Management
- Implement vulnerability management
- Prioritize remediation efforts
Asset Identification and Conpot
- Deploy ICS honeypots
- Analyze honeypot data
ICS/SCADA Scanning
- Perform safe ICS scanning
- Minimize operational risks
Metasploit and ICS/SCADA
- Use Metasploit for ICS testing
- Develop ICS exploits
Metasploit and Modbus
- Exploit Modbus protocols
- Use Modbus-specific modules
Metasploit and BACnet
- Exploit BACnet protocols
- Use BACnet-specific modules
Vulnerability Severity
- Assess vulnerability severity
- Calculate risk scores
Common Vulnerability Scoring System (CVSS)
- Calculate CVSS scores
- Apply CVSS in ICS environments
Standards and Regulation for Cybersecurity
Standards and Regulations
- Understand regulatory landscape
- Apply compliance requirements
ISO 27001
- Implement ISO 27001
- Maintain ISMS
CFATS
- Apply CFATS requirements
- Develop site security plans
IEC 62443
- Implement IEC 62443
- Design secure ICS architectures
NIST SP 800-82
- Apply NIST SP 800-82
- Implement NIST controls
Defense in Depth Strategy
- Design defense in depth
- Implement layered security
Industry Best Practices for ICS
- Apply industry best practices
- Develop security baselines
ICS/SCADA Regulations Workshop
- Conduct compliance assessments
- Prepare for audits
Securing the ICS/SCADA Network
Physical Security
- Implement physical security
- Design access controls
Securing the ICS Protocols
- Secure ICS protocols
- Implement protocol protections
IPsec
- Configure IPsec
- Implement secure tunnels
IPsec Modes
- Select IPsec modes
- Configure mode-specific settings
IPsec Rules
- Create IPsec policies
- Manage security rules
Firewall Scripting
- Develop firewall scripts
- Automate rule management
Isolating a Server
- Implement server isolation
- Design segmentation architectures
ICS Vulnerability Assessment and Risk Management
- Assess ICS risks
- Develop mitigation plans
ICS Testing
- Conduct safe ICS testing
- Develop test procedures
Bridging the Air Gap
ICS/SCADA Connections
- Secure ICS connections
- Implement data diodes
Next Generation Firewall
- Deploy NGFWs
- Configure advanced features
ICS Monitoring
- Implement ICS monitoring
- Detect anomalies
Log Aggregation
- Implement log aggregation
- Configure log collection
Zone Monitoring
- Monitor security zones
- Detect zone violations
SIEM
- Deploy SIEM solutions
- Develop correlation rules
Information Management
- Manage security information
- Implement data governance
Reports and Alerts
- Create security reports
- Configure alerts
Incident Investigation and Response
- Investigate incidents
- Execute response procedures
Log Storage and Retention
- Plan log storage
- Implement retention policies
Introduction to Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)
Why Intrusion Detection?
- Justify IDS deployment
- Understand detection needs
Intrusion Detection 101
- Understand IDS fundamentals
- Compare detection methods
IDS Features
- Evaluate IDS features
- Select appropriate capabilities
Topology Concerns
- Design IDS topology
- Optimize sensor placement
Under Attack
- Detect active attacks
- Minimize false positives
Intrusion Prevention
- Deploy IPS solutions
- Configure prevention rules
Types of IPS
- Compare IPS types
- Select appropriate solutions
Intrusion Analysis
- Analyze intrusion alerts
- Reconstruct attacks
Signs of Compromise
- Identify IOCs
- Detect system compromise
Log Analysis
- Analyze security logs
- Identify attack patterns
Malware
- Detect malware
- Analyze malware behavior
APT Defined
- Understand APTs
- Detect APT activity
MITRE ATT&CK Matrix
- Apply ATT&CK framework
- Map detection capabilities
Event Correlation
- Implement event correlation
- Develop correlation rules
ICS Malware
- Identify ICS malware
- Implement ICS-specific detection
How do I earn this certification?
Passing ICS-SCADA earns the ICS/SCADA Cybersecurity Specialist certification. It sits in the Industrial Control Systems Security track.
- CPENT - Certified Penetration Testing Professional
- LPT Master - Licensed Penetration Tester Master
- ECIH - EC-Council Certified Incident Handler
- CCISO - Certified Chief Information Security Officer Executive-level ICS security governance
- ECSA - EC-Council Certified Security Analyst Advanced ICS penetration testing skills
- CHFI - Computer Hacking Forensic InvestigatorICS incident investigation and forensics
- CTIA - Certified Threat Intelligence Analyst ICS threat intelligence and analysis
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for ICS-SCADA is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- ACTIVE
- Last content update: 2024-03-01
- OPC UA 1.05 Increased focus on OPC UA security in future exam updates • Release date: 2024-06-01
- IEC 61850 Edition 2.1 Enhanced coverage of substation automation security • Release date: 2024-03-15
- Modbus Security Modbus/TCP Security New Modbus security implementation guidelines • Release date: 2024-01-10
Who should take this exam?
This exam is typically taken by System Administrators, Engineers, and other IT professionals administering, patching, securing SCADA, and/or ICS and Security Consultants performing security assessments of SCADA and/or ICS.
- One year of work experience in Information Security domain
- Linux operating system fundamentals, including basic command line usage
- Conceptual knowledge of programming/scripting
- Solid grasp of essential networking concepts (OSI model, TCP/IP, networking devices, and transmission media)
- Understanding of basic security concepts (e.g., malware, intrusion detection systems, firewalls, and vulnerabilities)
- Familiarity with network traffic inspection tools (Wireshark, TShark, or TCPdump)