
EC-CouncilCertified Penetration Testing Professional
Domain 6Objective 2
IoT Penetration Testing CPENT Practice Questions (Page 6)
Part of the Advanced Exploitation and IoT domain, which makes up ~17% of our current practice bank.
49questions here
10free pages
8concepts
Questions 26–30
- 26
A penetration tester is assessing a smart-building deployment. The system includes BLE-enabled door locks, a Zigbee mesh of environmental sensors, an MQTT broker on-premises, and a cloud-based management portal. The tester wants to identify the most likely entry point for an attacker who is not physically on-site. Which attack surface should be prioritized first?
Select an answer first - 27
A tester is assessing a wireless door lock that uses a 433 MHz RF remote. The tester captures a valid 'unlock' signal. The tester wants to demonstrate that an attacker can unlock the door without the original remote. Which attack should the tester perform?
Select an answer first - 28
What is the primary purpose of the JTAG interface in IoT hardware hacking?
Select an answer first - 29
You are planning a penetration test for a smart factory. The environment includes sensors, actuators, a local gateway, a cloud backend, and a mobile app for monitoring. The client wants you to focus on the attack surface that is most likely to be exposed to the internet. Which component should you prioritize?
Select an answer first - 30
During a hardware assessment, you find a set of test points on the PCB that are labeled 'TMS', 'TCK', 'TDI', and 'TDO'. You suspect these are JTAG pins. What is the MOST likely benefit of connecting to these pins?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.