
EC-CouncilCertified Ethical Hacker
Domain 7Objective 1
Mobile Attack Vectors and OWASP Mobile Top 10 CEH Practice Questions (Page 6)
Part of the Mobile, IoT and OT Hacking domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 2–4 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
Questions 26–30
- 26
A mobile app security tester is evaluating an app that uses a WebView to display login pages. The tester discovers that the WebView allows JavaScript and has a JavaScript interface that exposes a method to access the device's file system. Which OWASP Mobile Top 10 risk is most critical, and what is the best mitigation?
Select an answer first - 27
A company's mobile devices are being infected with spyware that records keystrokes and sends them to an external server. The devices are managed by an MDM solution, and the spyware was installed via a malicious app that requested accessibility service permissions. Which combination of measures would best prevent this type of attack?
Select an answer first - 28
A mobile app developer wants to ensure that a banking app cannot be easily reverse-engineered and that its code is not tampered with after installation. Which combination of Android platform security features should the developer rely on?
Select an answer first - 29
Which OWASP Mobile Top 10 risk is most directly associated with an app that stores user credentials in plain text in a local database?
Select an answer first - 30
A user's smartphone suddenly displays a lock screen demanding a ransom payment in cryptocurrency, and all photos and contacts are inaccessible. Which type of mobile malware is this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.