
EC-CouncilCertified Security Specialist
Domain 4Objective 4
Mobile, IoT, and OT Attacks ECSS Practice Questions (Page 1)
Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.
51questions here
11free pages
10concepts
Questions 1–5
- 1
A security analyst is investigating a breach in an OT environment. The initial entry point was a phishing email sent to an employee in the corporate IT department. The attacker then moved laterally to the OT network. Which attack vector is described?
Select an answer first - 2
Which of the following is a common IoT vulnerability that arises from manufacturers shipping devices with easily guessable login credentials?
Select an answer first - 3
A mobile app development team wants to integrate security testing into their CI/CD pipeline. They need to identify common vulnerabilities like insecure data storage and hardcoded secrets before release. Which tool or technique is best suited for this automated, pre-release phase?
Select an answer first - 4
Which technique is recommended to mitigate risks when performing penetration testing on live OT systems?
Select an answer first - 5
A security consultant is evaluating a new IoT device for a client. The device uses default credentials, communicates over HTTP, and has no mechanism for firmware updates. Which vulnerability is the most critical to address first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.