
EC-CouncilCertified Ethical Hacker
Domain 7Objective 2
Android and iOS Hacking CEH Practice Questions (Page 10)
Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
12concepts
Questions 46–50
- 46
A company uses an MDM solution to manage both Android and iOS devices. The security team wants to test whether the MDM can prevent data leakage from a compromised device. Which MDM control is most effective in preventing data leakage from a rooted/jailbroken device?
Select an answer first - 47
You are conducting a security assessment of a mobile app that is available on both Android and iOS. The app uses HTTPS with certificate pinning, stores sensitive data locally, and uses a custom URL scheme for deep linking. You have rooted Android and jailbroken iOS test devices. Which of the following are appropriate steps for a comprehensive assessment? (Select all that apply.)
Select an answer first - 48
You are analyzing an Android app that uses native code for cryptographic operations. The app also has a WebView that loads content from a remote server and enables JavaScript. You need to determine if the native library contains hardcoded secrets. Which of the following is the most effective approach?
Select an answer first - 49
A penetration tester is analyzing an Android app that uses a native library for license validation. The tester has decompiled the DEX code and found that the license check is performed in native code. The tester wants to bypass the license check without modifying the app's code. Which approach is most effective?
Select an answer first - 50
An Android app you are testing uses the device's root access to read a protected system file. The app is not a system app and is installed on a rooted device. The app also uses the Accessibility Service to read screen content. Which security control is most likely to be bypassed by the app's use of root access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.