Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 4Objective 4

Mobile, IoT, and OT Attacks ECSS Practice Questions (Page 9)

Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.

51questions here
11free pages
10concepts

Questions 41–45

  1. 41application · medium

    A penetration tester is assessing a company's mobile app that is distributed only through the Apple App Store. The tester wants to identify vulnerabilities that could be exploited by a malicious app installed on the same device. Which approach is most appropriate?

    Select an answer first
  2. 42application · medium

    A security consultant is performing a penetration test on a smart building's IoT lighting system. The devices communicate over Zigbee and have a local web interface for configuration. The consultant wants to enumerate the attack surface before attempting any exploit. Which action is the most appropriate first step?

    Select an answer first
  3. 43foundation · easy

    Why do many OT environments rely on legacy systems that are difficult to secure?

    Select an answer first
  4. 44application · medium

    A company is developing a mobile app for both iOS and Android. The security team wants to ensure that the app does not store sensitive data insecurely on the device. Which platform-specific feature should be used to securely store sensitive data?

    Select an answer first
  5. 45foundation · easy

    Which of the following is an attack surface commonly found on IoT devices?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.