
EC-CouncilCertified Ethical Hacker
Domain 7Objective 4
IoT Attacks and Methodology CEH Practice Questions (Page 2)
Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
9concepts
Questions 6–10
- 6
A company is deploying a fleet of IoT sensors that communicate using MQTT. The security team wants to mitigate the risk of unauthorized devices publishing false data. Which control is most effective?
Select an answer first - 7
Which IoT communication protocol is known for its low power consumption and short-range communication, but is vulnerable to jamming and eavesdropping?
Select an answer first - 8
A security tester is assessing a smart TV that has a USB port, Wi-Fi, and an Ethernet port. The tester wants to find a way to extract the device's firmware without opening the case. Which attack vector is most appropriate?
Select an answer first - 9
An IoT penetration tester is following a systematic methodology. The tester has identified a target device and performed network scanning, discovering an open Telnet port. The tester attempts to connect using default credentials and succeeds. According to the IoT attack methodology, what is the next phase?
Select an answer first - 10
Which exploitation technique involves injecting malicious operating system commands into an application that passes user input to a system shell?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.