Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 7Objective 5

IoT and OT Attacks and Countermeasures EHE Practice Questions (Page 5)

Part of the Wireless, Mobile, IoT, and OT Attacks domain, which makes up ~15% of our current practice bank.

54questions here
11free pages
8concepts

Questions 21–25

  1. 21application · medium

    A smart building management system uses IoT sensors to control HVAC and lighting. The sensors communicate with a central controller via a wireless protocol that is not encrypted. An attacker with a radio transceiver can capture and replay sensor readings to manipulate the system. Which attack vector is being exploited?

    Select an answer first
  2. 22application · medium

    A manufacturing plant's OT network was hit by ransomware that encrypted the engineering workstations. The plant manager wants to restore operations quickly. The backup strategy includes nightly backups of the engineering workstations but not the PLC configurations. What is the most important lesson from this incident?

    Select an answer first
  3. 23application · medium

    A hospital deploys IoT infusion pumps that communicate with a central monitoring system. The pumps have a web interface for configuration that is accessible from the hospital's general IT network. The security team wants to reduce the risk of an attacker tampering with pump settings. Which control would be most effective?

    Select an answer first
  4. 24foundation · easy

    Which OT security countermeasure is most effective in detecting anomalous behavior on an industrial control network, such as unexpected Modbus commands?

    Select an answer first
  5. 25expert · hard

    A regional electricity utility is modernizing its OT environment. The utility must maintain 99.99% availability for its grid control systems. The security team proposes two initiatives: (1) deploying an inline intrusion prevention system (IPS) that can drop malicious packets, and (2) implementing a security information and event management (SIEM) system that collects logs from all OT devices. The utility's risk assessment shows that the most likely attack is a spear-phishing campaign targeting engineers. Which initiative should be prioritized?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.