
EC-CouncilIoT Security Essentials
Domain 5Objective 3
Vulnerability Databases (National Vulnerability Database, US-CERT, Shodan) ISE Practice Questions (Page 7)
Part of the Cloud Security and Threat Intelligence domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
10concepts
Questions 31–35
- 31
How do US-CERT bulletins typically differ from alerts and advisories?
Select an answer first - 32
Which Shodan search query would help identify devices exposing an unauthenticated Redis service?
Select an answer first - 33
What is the primary purpose of the National Vulnerability Database (NVD)?
Select an answer first - 34
A vulnerability management team is responding to a newly published CISA advisory about a critical vulnerability in a widely used IoT protocol library. The advisory includes a CVE ID but no CVSS score. The team needs to prioritize remediation across thousands of devices. The team has access to the NVD and Shodan. Which approach best balances speed and accuracy?
Select an answer first - 35
An analyst needs to find all CVEs that affect a specific product and have a CVSS score above 8.0. The analyst wants to automate this process to run weekly. Which approach is most efficient?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.