
EC-CouncilCertified Penetration Testing Professional
Domain 6Objective 2
IoT Penetration Testing CPENT Practice Questions (Page 7)
Part of the Advanced Exploitation and IoT domain, which makes up ~17% of our current practice bank.
49questions here
10free pages
8concepts
Questions 31–35
- 31
In an IoT penetration test, what does 'pivoting' refer to?
Select an answer first - 32
You are testing a smart home system that uses MQTT for device-to-cloud communication. The devices publish sensor data to a broker, and a mobile app subscribes to receive updates. During testing, you notice that the MQTT broker allows anonymous connections. Which of the following attacks would you prioritize to demonstrate the most significant security impact?
Select an answer first - 33
You are testing a wireless IoT device that uses a proprietary protocol at 915 MHz. You have a software-defined radio (SDR) and have captured a signal that appears to be a command. You want to determine if the protocol is susceptible to replay attacks. What is the FIRST step you should take?
Select an answer first - 34
During a CPENT engagement, you are assessing a smart building controller. You have physical access to the device and have successfully extracted the firmware image from the flash chip using an SPI programmer. Your goal is to identify hardcoded credentials that may allow you to gain a foothold on the device's management interface. Which of the following is the MOST efficient next step?
Select an answer first - 35
A tester is assessing a smart building with multiple IoT devices. The tester has identified that the MQTT broker is exposed to the internet and allows anonymous access. The tester wants to demonstrate the impact of this vulnerability. Which action would best demonstrate the impact?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.