
EC-CouncilEthical Hacking Essentials
Domain 7Objective 5
IoT and OT Attacks and Countermeasures EHE Practice Questions (Page 11)
Part of the Wireless, Mobile, IoT, and OT Attacks domain, which makes up ~15% of our current practice bank.
54questions here
11free pages
8concepts
Questions 51–54
- 51
A hospital deploys IoT infusion pumps that connect to the network. The pumps run an outdated firmware with known vulnerabilities, and the vendor is slow to release patches. The security team wants to reduce the risk of a ransomware attack spreading from the pumps to the rest of the network. Which control is most effective in this situation?
Select an answer first - 52
Which OT attack type is most commonly used as an initial vector to gain a foothold in an OT network by tricking an employee into opening a malicious attachment?
Select an answer first - 53
A security analyst notices that a large number of IoT devices on the corporate network are sending DNS queries to a suspicious domain. Further investigation reveals that the devices were compromised and are part of a botnet used for DDoS attacks. The analyst needs to contain the threat and prevent future recruitment. Which immediate action is most effective?
Select an answer first - 54
A hospital is deploying IoT medical devices that are critical for patient care. The devices have known vulnerabilities, and the vendor provides patches but only during scheduled maintenance windows. The security team wants to minimize the risk of exploitation while ensuring device availability. Which approach best balances security and availability?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to EHE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.