
EC-CouncilCertified Ethical Hacker
Domain 7Objective 4
IoT Attacks and Methodology CEH Practice Questions (Page 9)
Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
9concepts
Questions 41–45
- 41
Which of the following is a common IoT attack vector that involves exploiting the device's physical ports, such as UART or JTAG?
Select an answer first - 42
Which tool is commonly used to extract a filesystem from an IoT firmware image for analysis?
Select an answer first - 43
A smart home hub uses MQTT to communicate with sensors and actuators. A security auditor wants to test the security of the MQTT implementation. Which vulnerability is most commonly associated with MQTT deployments?
Select an answer first - 44
A smart lighting system uses Zigbee for communication. A security tester wants to assess the risk of unauthorized control of the lights. Which Zigbee-specific vulnerability should the tester consider?
Select an answer first - 45
An ethical hacker is conducting an IoT penetration test for a client. The client has provided a list of IoT device IP addresses but no credentials. The hacker has completed the reconnaissance phase and identified that some devices are running a known vulnerable firmware version. According to a systematic IoT attack methodology, what should the hacker do next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.