Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 7Objective 2

Android and iOS Hacking CEH Practice Questions (Page 8)

Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
12concepts

Questions 36–40

  1. 36application · medium

    During a code review of an Android app, you find that it stores a database in the app's private directory with world-readable permissions. The app also has a broadcast receiver that is exported and performs an action based on the data in the received intent. What is the most significant risk?

    Select an answer first
  2. 37expert · hard

    A company's MDM policy prohibits rooting Android devices. However, a security researcher needs to root a test device to perform a deep security assessment of a corporate app. The researcher also needs to access the app's private data directory. Which of the following is the most appropriate approach?

    Select an answer first
  3. 38application · medium

    A security researcher is analyzing an iOS app that stores a sensitive authentication token in the Keychain. The app runs on a non-jailbroken device. The researcher wants to determine if the token is accessible to other apps or if it is protected by the device passcode. Which iOS security feature is most relevant to this assessment?

    Select an answer first
  4. 39foundation · easy

    Which iOS component is a secure, encrypted database used to store small pieces of sensitive data like passwords and tokens, but can be a target if an app stores data with weak access controls?

    Select an answer first
  5. 40expert · hard

    A security consultant is reviewing an Android app that uses multiple activities, services, and receivers. The app's manifest shows that a service is exported and a receiver is also exported. The consultant wants to identify the most critical attack vector that could lead to data leakage. Which component should be prioritized?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.