
EC-CouncilCertified Security Specialist
Domain 4Objective 4
Mobile, IoT, and OT Attacks ECSS Practice Questions (Page 9)
Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.
51questions here
11free pages
10concepts
Questions 41–45
- 41
A penetration tester is assessing a company's mobile app that is distributed only through the Apple App Store. The tester wants to identify vulnerabilities that could be exploited by a malicious app installed on the same device. Which approach is most appropriate?
Select an answer first - 42
A security consultant is performing a penetration test on a smart building's IoT lighting system. The devices communicate over Zigbee and have a local web interface for configuration. The consultant wants to enumerate the attack surface before attempting any exploit. Which action is the most appropriate first step?
Select an answer first - 43
Why do many OT environments rely on legacy systems that are difficult to secure?
Select an answer first - 44
A company is developing a mobile app for both iOS and Android. The security team wants to ensure that the app does not store sensitive data insecurely on the device. Which platform-specific feature should be used to securely store sensitive data?
Select an answer first - 45
Which of the following is an attack surface commonly found on IoT devices?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.