Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 7Objective 4

IoT Attacks and Methodology CEH Practice Questions (Page 5)

Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
9concepts

Questions 21–25

  1. 21application · medium

    After compromising an IoT gateway, an attacker wants to move laterally to other devices on the same network. Which post-exploitation technique would facilitate lateral movement?

    Select an answer first
  2. 22expert · hard

    A security researcher is testing a smart doorbell that has a web interface, a mobile app, and a cloud backend. The researcher found that the mobile app does not validate the SSL certificate of the cloud backend. Which attack is most likely to succeed?

    Select an answer first
  3. 23foundation · easy

    Which security control is most effective in mitigating the risk of default credentials being used to compromise IoT devices?

    Select an answer first
  4. 24foundation · easy

    Which best practice helps mitigate the risk of firmware-based attacks on IoT devices?

    Select an answer first
  5. 25foundation · easy

    Which technique is commonly used to discover IoT devices on a network by sending probes to identify active hosts and their open ports?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.