
EC-CouncilCertified Ethical Hacker
Domain 7Objective 4
IoT Attacks and Methodology CEH Practice Questions (Page 6)
Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
9concepts
Questions 26–30
- 26
Which of the following is a primary component of an IoT device that often presents an attack surface through its debug interfaces and configuration pins?
Select an answer first - 27
Which post-exploitation activity involves using a compromised IoT device as a pivot point to attack other devices on the network?
Select an answer first - 28
Which phase of the IoT attack methodology involves actively probing the target device to identify vulnerabilities that can be exploited?
Select an answer first - 29
A security analyst is investigating a suspected rogue IoT device on a network. The analyst has captured network traffic and wants to identify the device type. Which technique is most effective?
Select an answer first - 30
An IoT penetration tester is assessing a smart factory. The tester has completed reconnaissance and scanning, and has identified a PLC with a known unauthenticated remote code execution vulnerability. However, exploiting the vulnerability could cause the PLC to crash, disrupting production. The client has stated that production downtime must be minimized. What should the tester do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.