
EC-CouncilCertified Ethical Hacker
Domain 7Objective 4
IoT Attacks and Methodology CEH Practice Questions (Page 4)
Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
9concepts
Questions 16–20
- 16
A company is deploying smart locks for office doors. The locks use Zigbee and are managed by a central hub. The security team wants to prevent unauthorized devices from joining the Zigbee network. Which control is most effective?
Select an answer first - 17
A security consultant is performing a threat model for a new smart vending machine. The machine has a web-based admin interface, a Bluetooth Low Energy (BLE) payment reader, and a USB port for maintenance. Which attack surface is most likely to be exploited by an attacker who is physically near the machine but not connected to its network?
Select an answer first - 18
After compromising an IoT device, which post-exploitation activity involves installing a backdoor or modifying the firmware to maintain access?
Select an answer first - 19
A company is deploying IoT devices that use MQTT for communication. The security team wants to implement a control that will prevent unauthorized devices from connecting to the broker. Which control is most effective?
Select an answer first - 20
A company is deploying IoT devices that use both BLE and MQTT. The security team wants to mitigate the risk of unauthorized access and data tampering. They have limited budget and must choose one control. Which control provides the most comprehensive mitigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.