Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 7Objective 3

Mobile Attack Vectors and Vulnerabilities EHE Practice Questions (Page 8)

Part of the Wireless, Mobile, IoT, and OT Attacks domain, which makes up ~15% of our current practice bank.

47questions here
10free pages
8concepts

Questions 36–40

  1. 36expert · medium

    A security analyst is testing the security of a corporate Wi-Fi network. The analyst uses a laptop to set up a rogue access point with the same SSID as the corporate network but with no encryption. Several employees' phones automatically connect to the rogue AP. The analyst then captures traffic and sees plaintext credentials for a web application. Which vulnerability is being exploited?

    Select an answer first
  2. 37application · medium

    A company issues laptops to employees who work in public spaces. A laptop is stolen from a coffee shop. Which control would have most effectively protected the data on the laptop?

    Select an answer first
  3. 38application · medium

    A security analyst is evaluating the security of a new Android device model for corporate use. The device supports hardware-backed keystore, verified boot, and app sandboxing. The analyst wants to ensure that if the device is lost, the data on it remains protected. Which feature should the analyst verify is enabled by default?

    Select an answer first
  4. 39expert · medium

    A mobile app developer is reviewing the security of a finance app. The app uses a third-party library for analytics, which sends device information and usage data to the library's servers. The developer discovers that the library also has a known vulnerability that allows remote code execution. The app is not using the latest version of the library. What is the most immediate risk and the best action?

    Select an answer first
  5. 40application · easy

    An employee receives a text message that appears to be from their bank, asking them to click a link and verify their account. The employee clicks the link and enters their credentials. Which attack vector was used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.