CEH Wireless, IoT and Cloud Security Practice Question
A security analyst is investigating a potential compromise of a Zigbee-based smart home network. The analyst notices that an unauthorized device has joined the network and is communicating with other devices. The network uses the default Trust Center Link Key. Which of the following is the most likely cause of the unauthorized device joining the network?
⚠ Common exam trap
The trap here is focusing on the network key or encryption features, when the immediate enabler is the default Trust Center Link Key that is widely known and used for initial joining.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The network is using the default Trust Center Link Key, which is publicly known and allows any device with that key to join if the network is not using additional authentication.
The default Trust Center Link Key in Zigbee is a global key that is publicly known. If the network does not change this key or use install codes, any device with the default key can join the network. This is a common misconfiguration in Zigbee deployments. The unauthorized device likely used the default key to authenticate with the Trust Center and join the network, allowing it to communicate with other devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The network is using a weak network key that was cracked by the attacker, allowing the device to join after deriving the key.
Why it's wrong here
While a weak network key could be cracked, the scenario specifically mentions the default Trust Center Link Key, not the network key. The Trust Center Link Key is used for key establishment, and if it is default, it directly allows joining. Cracking the network key would require additional steps and is not the primary issue here. The default Trust Center Link Key is the immediate vulnerability.
- ✗
The network is not using Zigbee security features, such as frame counters or encryption, allowing any device to join without authentication.
Why it's wrong here
Zigbee networks always use encryption and frame counters at the MAC layer. Disabling security features would be a misconfiguration, but the scenario implies the network is operational and using the default Trust Center Link Key. The presence of an unauthorized device is more directly explained by the default key, not by the absence of security features, which would likely cause broader issues.
- ✗
The network is using Zigbee 3.0 with install codes, but the install code was not properly configured, allowing the device to join with the default key.
Why it's wrong here
Zigbee 3.0 with install codes enhances security by using a unique link key derived from the install code. If the install code was not properly configured, the device might not join at all or might use a default key only if the network falls back. However, the scenario states the network uses the default Trust Center Link Key, so the presence of install codes is not the cause. The issue is the default key itself.
- ✓
The network is using the default Trust Center Link Key, which is publicly known and allows any device with that key to join if the network is not using additional authentication.
Why this is correct
The default Trust Center Link Key in Zigbee is a well-known value (e.g., 'ZigBeeAlliance09') that is used for initial communication with the Trust Center. If the network does not enforce unique link keys or install codes, an attacker can use this default key to join the network and communicate with devices. This is the most likely cause of the unauthorized device joining.
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.