Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 4Objective 4

Mobile, IoT, and OT Attacks ECSS Practice Questions (Page 2)

Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.

51questions here
11free pages
10concepts

Questions 6–10

  1. 6expert · hard

    A security analyst is investigating a cyber incident at a food processing plant. The plant's OT network was breached, and the attacker manipulated the temperature settings of pasteurization equipment, causing product spoilage. The initial access vector is believed to be a phishing email sent to an engineer who used a laptop that could connect to the OT network. Which combination of factors most likely enabled this attack?

    Select an answer first
  2. 7foundation · easy

    A user installs an app from an unofficial app store, and the app requests permissions to read contacts and send SMS. Which mobile attack vector is this an example of?

    Select an answer first
  3. 8application · medium

    A security analyst is reviewing the app store distribution for a new corporate productivity app. The app will handle sensitive HR data. The analyst wants to minimize the risk of malicious tampering and unauthorized distribution. Which distribution approach provides the strongest control over which devices can install the app?

    Select an answer first
  4. 9application · medium

    A security consultant is hired to conduct a penetration test on a manufacturing plant's OT environment. The plant uses legacy PLCs that are critical to production. The consultant wants to test the resilience of the PLCs to malformed packets. What is the most appropriate way to proceed?

    Select an answer first
  5. 10expert · hard

    A security analyst is investigating a cyber incident at a natural gas pipeline company. The attack started with a phishing email to an employee, then moved to the corporate network, and finally reached the OT network that controls the pipeline. The analyst finds that the OT network had no firewall between it and the IT network. What is the most likely reason the attacker could move from IT to OT?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.