Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 4Objective 4

Mobile, IoT, and OT Attacks ECSS Practice Questions (Page 8)

Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.

51questions here
11free pages
10concepts

Questions 36–40

  1. 36application · medium

    A mobile app developer has just completed an Android app that uses a WebView to display user-supplied content. The security team wants to test the app for common WebView vulnerabilities before release. Which testing approach would most directly identify a JavaScript injection flaw in the WebView?

    Select an answer first
  2. 37foundation · easy

    Which of the following is a common attack vector that specifically exploits the trust users place in text messages to deliver malicious links or request sensitive information?

    Select an answer first
  3. 38application · medium

    A manufacturer of smart thermostats discovers that a batch of devices shipped with a hardcoded root password in the firmware. The devices connect to the internet and are managed via a cloud service. Which vulnerability class does this issue represent, and what is the most immediate remediation?

    Select an answer first
  4. 39foundation · easy

    An IoT device sends sensor data to its cloud server without encryption, allowing an attacker on the same network to read the data. Which IoT vulnerability does this illustrate?

    Select an answer first
  5. 40expert · hard

    A penetration tester is assessing a mobile app that uses certificate pinning. The tester needs to intercept HTTPS traffic to analyze the app's API calls. Which technique is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.