Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 7Objective 1

Mobile Attack Vectors and OWASP Mobile Top 10 CEH Practice Questions (Page 1)

Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
6concepts

Questions 1–5

  1. 1application · medium

    A company allows employees to use personal smartphones for work email and calendar. The security team wants to reduce the risk of data leakage from malicious apps that request excessive permissions. Which approach best balances user privacy and corporate data protection?

    Select an answer first
  2. 2expert · hard

    A company is implementing a BYOD policy and must balance employee privacy with corporate security. The security team wants to enforce a minimum OS version, require a passcode, and be able to remotely wipe corporate data. Which MDM approach best meets these requirements while respecting employee privacy?

    Select an answer first
  3. 3expert · hard

    A security team is assessing the risk of a mobile app that uses a third-party SDK for analytics. The SDK is known to collect device identifiers and location data. The team must decide whether to keep the SDK. Which consideration is most critical from a mobile attack vector perspective?

    Select an answer first
  4. 4application · medium

    A company allows employees to bring their own devices (BYOD) to access corporate email. The security team wants to prevent corporate data from being leaked through malicious apps that request excessive permissions. Which combination of measures would best mitigate this risk while preserving employee privacy?

    Select an answer first
  5. 5expert · hard

    A security team is investigating a mobile device that is part of a botnet. The device is not rooted, but the team finds a malicious app that was installed from a third-party store. The app is using the device's camera and microphone without the user's knowledge. Which combination of factors allowed this attack to succeed?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.