
EC-CouncilCertified Security Specialist
Domain 4Objective 4
Mobile, IoT, and OT Attacks ECSS Practice Questions (Page 7)
Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.
51questions here
11free pages
10concepts
Questions 31–35
- 31
A mobile security team is testing a banking app that uses certificate pinning. The team wants to perform dynamic analysis to intercept and modify the app's HTTPS traffic. The app is running on a non-rooted Android device. Which approach is most likely to succeed?
Select an answer first - 32
Which of the following is a known security weakness of the Android platform compared to iOS?
Select an answer first - 33
A penetration tester is planning a test on a live chemical plant's OT network. The plant cannot tolerate any interruption to the production process. Which testing approach best balances the need for security assessment with the plant's operational constraints?
Select an answer first - 34
Which of the following is a unique security challenge in OT environments compared to traditional IT?
Select an answer first - 35
A penetration tester is asked to assess the security of a remote oil pumping station that is connected to the central SCADA system via a satellite link. The station has limited bandwidth and the pumping process cannot be interrupted. The tester wants to test the SCADA protocol for vulnerabilities. Which approach is most appropriate given the constraints?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.