
EC-CouncilCertified Ethical Hacker
Domain 7Objective 1
Mobile Attack Vectors and OWASP Mobile Top 10 CEH Practice Questions (Page 2)
Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
Questions 6–10
- 6
During a mobile app security assessment, a tester uses a jailbroken iOS device to inspect the app's file system and finds a plist file containing plaintext passwords. Which OWASP Mobile Top 10 risk does this demonstrate, and what is the best remediation?
Select an answer first - 7
A security analyst is investigating a suspicious Android app that was sideloaded onto a user's device. The analyst wants to determine whether the app has been tampered with after it was originally signed. Which check should the analyst perform?
Select an answer first - 8
A security tester is assessing a mobile app and wants to check whether it transmits sensitive data over the network in an insecure manner. Which testing technique is most appropriate?
Select an answer first - 9
An organization's mobile devices are being infected with ransomware that encrypts files and demands payment. The infections started after users installed apps from a third-party store. Which combination of measures would best prevent future infections?
Select an answer first - 10
A security analyst is categorizing mobile device threats for a risk assessment. Which of the following correctly pairs a mobile attack vector with its category?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.