
EC-CouncilCertified Security Specialist
Domain 4Objective 4
Mobile, IoT, and OT Attacks ECSS Practice Questions (Page 10)
Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.
51questions here
11free pages
10concepts
Questions 46–50
- 46
A penetration tester is assessing an IoT device that uses a proprietary protocol over Wi-Fi. The tester wants to analyze the firmware for backdoors and hardcoded credentials. Which step should the tester perform first?
Select an answer first - 47
A penetration testing firm is contracted to assess a power utility's OT environment. The utility has a strict policy that no active scanning or exploitation may be performed on production systems. However, the utility wants to test the effectiveness of its security monitoring. Which testing approach best satisfies the client's constraint while still providing meaningful security insights?
Select an answer first - 48
A penetration tester is assessing a smart camera that uses an MQTT broker for telemetry. The tester wants to analyze the device's firmware for hardcoded secrets and insecure configurations. Which technique is the most appropriate for this task?
Select an answer first - 49
In an ICS architecture, which component is a specialized computer that controls industrial processes based on inputs from sensors?
Select an answer first - 50
A penetration testing firm is hired to assess a water treatment facility's OT network. The facility uses legacy PLCs that are critical to the treatment process. The test must not cause any disruption to the water supply. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.