Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 7Objective 2

Android and iOS Hacking CEH Practice Questions (Page 7)

Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
12concepts

Questions 31–35

  1. 31expert · hard

    You are analyzing an iOS app that uses a custom URL scheme to handle deep links. The app also stores a session token in the keychain with the kSecAttrAccessibleWhenUnlocked attribute. You discover that the URL scheme handler does not validate the source of the URL and that the app uses a vulnerable version of a third-party library that is susceptible to memory corruption. Which of the following is the most critical risk?

    Select an answer first
  2. 32application · medium

    A security team is testing an iOS app that uses certificate pinning to prevent man-in-the-middle attacks. The team has a jailbroken test device and wants to bypass the pinning to intercept HTTPS traffic. Which approach is most effective?

    Select an answer first
  3. 33application · medium

    An iOS app uses the Keychain to store a session token but does not set a data protection class, so it defaults to 'Always' (accessible even when the device is locked). A tester wants to demonstrate the risk of this misconfiguration. Which attack scenario is most relevant?

    Select an answer first
  4. 34foundation · easy

    Which Android component is often misconfigured to allow arbitrary JavaScript execution and file access, making it a common target for attacks that steal cookies or inject malicious scripts?

    Select an answer first
  5. 35application · medium

    An Android app has a WebView that loads remote content from a URL that includes user-supplied parameters. The app also enables JavaScript and does not restrict the URL scheme. A tester wants to demonstrate that a malicious URL can execute JavaScript in the WebView context. Which technique is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.