Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 6Objective 2

IoT Penetration Testing CPENT Practice Questions (Page 8)

Part of the Advanced Exploitation and IoT domain, which makes up ~17% of our current practice bank.

49questions here
10free pages
8concepts

Questions 36–40

  1. 36application · medium

    During an IoT penetration test, you found that the MQTT broker uses no authentication and the companion mobile app stores the broker password in plaintext in its configuration file. Which of the following recommendations would you include in the report to address BOTH findings?

    Select an answer first
  2. 37application · medium

    You have extracted a firmware image from an IoT device and mounted the filesystem. You find a script that contains a hardcoded password for a database. The database is on a remote server. What is the MOST appropriate way to validate this finding without causing damage?

    Select an answer first
  3. 38application · medium

    You have gained a root shell on an IoT device via a firmware backdoor. The device is on a separate IoT network segment. Your goal is to pivot to the corporate network. Which of the following is the MOST appropriate first step?

    Select an answer first
  4. 39application · medium

    You are testing a smart lock's companion mobile app. The app communicates with the lock via Bluetooth Low Energy (BLE) and also with a cloud backend. During testing, you intercept the BLE traffic and notice that the unlock command is sent without any encryption or authentication. What is the MOST direct impact you can demonstrate?

    Select an answer first
  5. 40foundation · easy

    What is a key element of an IoT penetration testing report?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.