
EC-CouncilCertified Penetration Testing Professional
Domain 6Objective 2
IoT Penetration Testing CPENT Practice Questions (Page 3)
Part of the Advanced Exploitation and IoT domain, which makes up ~17% of our current practice bank.
49questions here
10free pages
8concepts
Questions 11–15
- 11
You are on an engagement where you have gained a root shell on an IoT device via a firmware backdoor. The device has two network interfaces: one on the IoT network (192.168.10.0/24) and one on the corporate network (10.0.0.0/24). The device's routing table only has a default route via the IoT network. You want to use the device as a pivot to scan the corporate network. Which of the following is the MOST effective approach?
Select an answer first - 12
You are writing a penetration test report for an IoT device. You found that the device's firmware contains hardcoded credentials for a cloud API, and the device uses MQTT to communicate with the cloud. The client wants to know the most critical risk and the most effective mitigation. Which of the following would you include in the report?
Select an answer first - 13
A tester is assessing a smart home system. The companion mobile app communicates with the cloud backend via HTTPS. The tester intercepts the traffic and notices that the app also sends device credentials in the URL query string. Which vulnerability is the tester most likely to report?
Select an answer first - 14
A tester is assessing a smart home system. The mobile app has a feature to reset the device to factory defaults. The tester discovers that the reset process does not require authentication. Which vulnerability is this?
Select an answer first - 15
A tester is evaluating a BLE-enabled fitness tracker. The tester wants to test for unauthorized access to the device's data. Which tool or technique is most appropriate for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.