
EC-CouncilCertified Penetration Testing Professional
Domain 6Objective 2
IoT Penetration Testing CPENT Practice Questions (Page 1)
Part of the Advanced Exploitation and IoT domain, which makes up ~17% of our current practice bank.
49questions here
10free pages
8concepts
Questions 1–5
- 1
A tester has compromised a smart thermostat and gained root access. The thermostat is on a separate IoT VLAN with a firewall that only allows outbound HTTPS to the cloud. The tester wants to exfiltrate data from the corporate network. Which technique is most effective?
Select an answer first - 2
In a typical IoT architecture, which component is primarily responsible for aggregating data from multiple sensors and forwarding it to the cloud?
Select an answer first - 3
You are analyzing an IoT device's firmware and find that the bootloader verifies the signature of the kernel before booting. You have physical access to the device and want to gain code execution. Which of the following approaches is MOST likely to succeed?
Select an answer first - 4
Which of the following is a common security weakness in CoAP (Constrained Application Protocol) deployments?
Select an answer first - 5
A tester is analyzing the firmware of a smart lock. The firmware image is encrypted, but the tester finds a bootloader that decrypts it in memory. Which technique should the tester use to extract the decrypted firmware?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.