
EC-CouncilCertified Security Specialist
Domain 4Objective 4
Mobile, IoT, and OT Attacks ECSS Practice Questions (Page 3)
Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.
51questions here
11free pages
10concepts
Questions 11–15
- 11
Which activity is part of the IoT penetration testing methodology to assess the device's network communications?
Select an answer first - 12
In mobile penetration testing, which technique involves examining the app's code without executing it to identify vulnerabilities?
Select an answer first - 13
Which system is typically used for wide-area monitoring and control of geographically dispersed infrastructure such as power grids and pipelines?
Select an answer first - 14
A penetration tester is assessing a company's mobile app that handles employee expense reports. The app is distributed through the company's MDM portal and also sideloaded on some personal devices. The tester discovers that the app stores authentication tokens in plaintext in SharedPreferences on Android and in NSUserDefaults on iOS. Which mobile attack vector is most directly enabled by this finding?
Select an answer first - 15
An attacker sends a highly targeted email to an OT engineer, impersonating a colleague to trick them into opening a malicious attachment. Which OT attack vector is this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.