
EC-CouncilCertified Ethical Hacker
Domain 7Objective 4
IoT Attacks and Methodology CEH Practice Questions (Page 8)
Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
9concepts
Questions 36–40
- 36
During firmware analysis, what is the primary purpose of extracting the filesystem from a firmware image?
Select an answer first - 37
Which IoT device component is most likely to expose an attack surface through its web-based management interface?
Select an answer first - 38
A security auditor is assessing a smart building where a new HVAC controller was just added to the network. The auditor wants to identify the device type, open ports, and any web-based admin interface without causing disruption. Which approach best fits the early reconnaissance phase of an IoT attack methodology?
Select an answer first - 39
Which IoT communication protocol is lightweight and commonly used for device-to-device communication, but often lacks built-in security mechanisms?
Select an answer first - 40
A smart agriculture company uses LoRaWAN for soil sensors and MQTT for a local gateway. The security team must choose a mitigation for a replay attack on the LoRaWAN uplink messages. Which control is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.