
EC-CouncilCertified Penetration Testing Professional
Domain 6Objective 2
IoT Penetration Testing CPENT Practice Questions (Page 5)
Part of the Advanced Exploitation and IoT domain, which makes up ~17% of our current practice bank.
49questions here
10free pages
8concepts
Questions 21–25
- 21
A tester has a smart plug that uses an SPI flash chip to store configuration data. The tester wants to extract the firmware and configuration without desoldering the chip. Which approach is most appropriate?
Select an answer first - 22
What is the primary purpose of extracting firmware from an IoT device during a penetration test?
Select an answer first - 23
You are testing a smart thermostat's companion mobile app. The app allows users to control the thermostat remotely via a cloud API. During testing, you find that the API endpoint for changing the temperature does not check if the user is authorized to control that specific thermostat. What is the MOST likely vulnerability?
Select an answer first - 24
A tester is assessing a wireless sensor network that uses Zigbee. The tester wants to test for unauthorized control of the devices. Which attack is most relevant?
Select an answer first - 25
After compromising a smart lighting hub, a tester wants to pivot to the corporate network. The hub is connected to a separate IoT VLAN that has a firewall rule allowing only MQTT traffic to the broker. Which technique would be most effective for the tester to establish a foothold on the corporate network?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.