Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 7Objective 2

Android and iOS Hacking CEH Practice Questions (Page 6)

Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
12concepts

Questions 26–30

  1. 26application · medium

    You are performing a security assessment of an Android app that handles sensitive financial data. The app is designed to run on both rooted and non-rooted devices. During testing, you need to intercept and modify the app's network traffic and inspect its internal storage. The app uses certificate pinning and stores a database in its private data directory. You have a rooted test device. Which approach is most effective for this assessment?

    Select an answer first
  2. 27expert · hard

    An iOS app uses a custom URL scheme to handle deep links. The app also uses the Keychain to store a session token. A tester discovers that the app does not validate the source of the URL and passes the URL parameters to a web service. Which attack is most likely to lead to account takeover?

    Select an answer first
  3. 28application · medium

    While analyzing an Android app, you find a content provider that is exported and has a method that reads files from the app's internal storage based on a path provided in the query. The app does not enforce any permission on the provider. What is the most direct way to exploit this vulnerability?

    Select an answer first
  4. 29application · medium

    During a mobile app assessment, you decompile an Android APK with jadx and notice that the app uses a WebView to display content from a remote server. The app enables JavaScript and adds a JavaScript interface that exposes a method to read files from the device's internal storage. The app also has an exported activity that can be launched by other apps. Which combination of issues should you report as the most critical?

    Select an answer first
  5. 30expert · hard

    An Android app is designed to run on both rooted and non-rooted devices. The app uses the Android Keystore to store a cryptographic key, but on a rooted device, an attacker with root access can potentially extract the key. The developer wants to mitigate this risk. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.