
EC-CouncilEthical Hacking Essentials
Domain 7Objective 3
Mobile Attack Vectors and Vulnerabilities EHE Practice Questions (Page 6)
Part of the Wireless, Mobile, IoT, and OT Attacks domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
8concepts
Questions 26–30
- 26
A company's custom mobile app stores user credentials in a local SQLite database and requests access to the device's contacts and SMS. A security review flags these practices. Which remediation best addresses the identified risks?
Select an answer first - 27
Which mobile platform vulnerability is primarily caused by the failure of an app to properly encrypt data it stores on the device?
Select an answer first - 28
During a security review, an app is found to request permission to access the camera, microphone, and location, but the app's core functionality only requires internet access. Which risk does this pose?
Select an answer first - 29
A company has a BYOD policy that allows employees to use personal phones for email and calendar. The MDM solution enforces a device PIN and can remotely wipe the device. Recently, an employee's phone was lost, and the company remotely wiped it. However, the employee later complained that their personal photos were also erased. Management wants to avoid this in the future while still protecting corporate data. Which approach best balances security and employee privacy?
Select an answer first - 30
A developer is reviewing a mobile banking app before release. The app requests access to the device's contacts, SMS, and location, although none of these are needed for its core banking functions. The developer also notices that the app stores the user's authentication token in plain text in SharedPreferences. Which two issues are most critical to address before launch?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.