312-50 exam dumps

312-50 practice question 423 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 423

Single answer▪ OT Attacks

During an authorized assessment of a manufacturing plant, you discover that several PLCs on the OT network communicate with the HMI using Modbus/TCP over port 502. The plant manager asks you to demonstrate a realistic attack path that could change a process value without exploiting a software vulnerability on the PLC itself. Which action would MOST directly achieve that objective in this environment?

  1. A

    Perform ARP spoofing between the HMI and PLC, then modify Modbus/TCP write commands in transit to alter register values

  2. B

    Launch a TCP SYN flood against the PLC so it reboots into a maintenance mode that accepts unauthenticated logic uploads

  3. C

    Exploit SQL injection on the HMI's historian database to automatically overwrite PLC holding registers

  4. D

    Send malformed DHCP replies to force the PLC to obtain a new IP address and reset its ladder logic

Show answer and explanation

Correct answer: A

Explanation

This question tests applied understanding of OT attack paths that target insecure industrial protocols rather than software vulnerabilities. Modbus/TCP is widely used in industrial control environments and, by design, does not provide authentication or encryption. In a flat network where an attacker can gain Layer 2 position, man-in-the-middle techniques such as ARP spoofing can allow interception and modification of commands between HMI and PLC. This aligns with well-known OT security guidance from organizations such as CISA and ICS-focused best practices, which emphasize network segmentation, protocol-aware monitoring, and restricting unauthorized access to control network segments. The key concept is that many OT attacks succeed by abusing trusted communications and weak protocol security, not by exploiting memory corruption or classic IT-style vulnerabilities on the controller itself.

  • A. Correct.

    Correct. In many legacy or flat OT environments, Modbus/TCP traffic is unencrypted and lacks built-in authentication. If the assessor can place themselves in the communication path using ARP spoofing on the local segment, they can observe and potentially alter Modbus function codes or data values, including write requests to coils or holding registers. This is a realistic OT attack because it abuses protocol trust rather than a software flaw in the PLC.

  • B. Incorrect.

    Incorrect. A SYN flood is a denial-of-service technique, not a reliable method for forcing a PLC into a special mode that accepts logic uploads. PLC maintenance or programming modes are vendor-specific and generally are not triggered by simple TCP resource exhaustion. This option reflects a common misconception that availability attacks automatically create a path to code execution or configuration changes.

  • C. Incorrect.

    Incorrect. While historian or HMI systems may use databases that could theoretically be vulnerable to SQL injection, compromising a database does not directly cause PLC holding registers to be overwritten unless there is a specific application workflow that writes database values back to the controller. The question asks for the most direct method to change a process value on the PLC network without exploiting the PLC itself.

  • D. Incorrect.

    Incorrect. DHCP manipulation may affect devices that rely on DHCP, but many PLCs in industrial environments use static addressing. Even when DHCP is used, changing a PLC's IP address would more likely disrupt communications than reset ladder logic. IP reconfiguration does not inherently alter control logic or process register values.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam