Courseiva

CEH · domain

Advanced Topics: Wireless, Cloud, IoT, Cryptography

This domain covers wireless encryption (WPA3/SAE, WPA2 flaws), cloud and IoT attack surfaces, and cryptographic weaknesses. CEH tests it through tool identification (Reaver, aircrack-ng), attack naming (collision, evil twin, rogue AP), and log or certificate analysis to classify the attack in scenario questions.

119 questions28 easy59 medium32 hard

Focused practice

Practice Advanced Topics: Wireless, Cloud, IoT, Cryptography questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Advanced Topics: Wireless, Cloud, IoT, Cryptography

Identify wireless protocols, cryptographic attacks, and cloud/IoT threats by name and tool. Most important: match each scenario to the correct attack class, especially WPA3 SAE versus WPA2 PSK, and distinguish hash collisions from other cryptographic failures.

WPA3 Simultaneous Authentication of Equals (SAE) replacing WPA2 pre-shared key exchange, adding forward secrecy

WPS PIN brute-force attacks using Reaver against Wi-Fi Protected Setup enabled access points

MD5 hash collision attacks producing identical digests from two distinct inputs

Rogue or untrusted certificate chain analysis indicating man-in-the-middle or spoofed CA issuance

Watch out for

Common Advanced Topics: Wireless, Cloud, IoT, Cryptography exam traps

  • ▸Confusing WPA3 SAE with WPA2-PSK: SAE resists offline dictionary attacks, WPA2 four-way handshake capture does not.
  • ▸Mixing up hash collision with preimage attack: collisions need two differing inputs with equal digests, not reversing a hash.
  • ▸Assuming any untrusted root CA means compromise; it may be a rogue, self-signed, or misconfigured intermediate chain.

Question index

All Advanced Topics: Wireless, Cloud, IoT, Cryptography questions (119)

Click any question to see the full explanation, or start a practice session above.

1

Which THREE of the following are common IoT attack vectors?

Medium
2

Which THREE of the following are valid defenses against WPA2 attacks? (Select three)

Hard
3

A security team is evaluating wireless security for a corporate network. They want to implement the strongest current encryption standard for Wi-Fi. Which of the following should they choose?

Medium
4

An IoT device uses MQTT protocol with default credentials 'admin/admin' and no TLS encryption. An attacker on the same network captures MQTT packets and extracts sensor data. Which two vulnerabilities are being exploited? (Choose the best combination)

Medium
5

A security engineer wants to ensure that a wireless network uses the most secure encryption available. Which of the following should be configured on the access point?

Medium
6

A security analyst captures a WPA2 4-way handshake using airodump-ng. Which tool would they use to perform a dictionary attack on the captured handshake to recover the PSK?

Easy
7

An attacker sets up a fake access point with the same SSID as a legitimate corporate network. Clients connecting to this AP are prompted to enter their network credentials. Which type of attack is this?

Medium
8

An IoT device uses the MQTT protocol without TLS. A security tester connects to the broker and subscribes to all topics using '#'. What is the tester MOST likely able to accomplish?

Medium
9

A penetration tester executes the following command: 'reaver -i wlan0mon -b 00:11:22:33:44:55 -vv'. Which attack is being performed?

Medium
10

Which TWO of the following are common attack vectors against IoT devices? (Select 2)

Medium
11

Which of the following is a cryptographic attack that exploits collisions in hash functions?

Medium
12

Which THREE of the following are characteristics of asymmetric encryption?

Medium
13

During a penetration test, a tester captures a WPA2 4-way handshake. Which of the following is the NEXT step to attempt to recover the Wi-Fi passphrase?

Medium
14

During a penetration test, an ethical hacker runs the following command: aireplay-ng -0 5 -a 00:11:22:33:44:55 -c 66:77:88:99:AA:BB wlan0mon. What is the immediate effect of this command?

Medium
15

An IoT device uses the MQTT protocol without TLS. An attacker on the same network captures messages and publishes a fake temperature reading. Which attack is being executed?

Hard
16

What is the primary purpose of the 4-way handshake in WPA/WPA2-Personal?

Easy
17

Which TWO of the following are common attack vectors against IoT devices? (Select TWO.)

Medium
18

A security analyst observes repeated de-authentication packets targeting clients on a corporate Wi-Fi network. What is the MOST likely goal of the attacker?

Medium
19

Which TWO of the following are cloud-specific security threats?

Easy
20

A security analyst captures a WPA2 4-way handshake using airodump-ng. Which tool would they most likely use next to attempt to crack the PSK using a wordlist?

Easy
21

Which tool is specifically designed to assess the security configuration of AWS, Azure, and GCP cloud environments by scanning for misconfigurations in services like S3, IAM, and EC2?

Easy
22

In PKI, what is the primary role of a Certificate Authority (CA)?

Easy
23

Which wireless security standard introduced in 2018 uses Simultaneous Authentication of Equals (SAE) to replace the pre-shared key exchange in WPA2, providing forward secrecy and resistance to offline dictionary attacks?

Easy
24

Which TWO tools are specifically designed for cloud security auditing and exploitation? (Choose two.)

Medium
25

A security analyst captures network traffic and sees the following: Client sends a SYN, server responds with SYN-ACK, then client sends ACK. Immediately after, the client sends an encrypted payload. This traffic is consistent with which phase of a WPA2 attack?

Hard
26

In the cloud shared responsibility model, which of the following is typically the responsibility of the customer when using AWS EC2 (IaaS)?

Medium
27

Which THREE of the following are common attack vectors against IoT devices? (Choose three.)

Hard
28

Which of the following cryptographic algorithms is classified as asymmetric?

Easy
29

During a penetration test, a tester captures the WPA2 4-way handshake with airodump-ng and then uses aircrack-ng with a wordlist. However, the PSK is not found. Which of the following is the MOST likely reason?

Medium
30

Which TWO of the following are asymmetric encryption algorithms? (Choose two.)

Easy
31

Which of the following attacks is characterized by an attacker placing a fake wireless access point with the same SSID as a legitimate network to capture client credentials?

Medium
32

An attacker uses Reaver against a Wi-Fi network. What vulnerability is the attacker primarily exploiting?

Medium
33

Which THREE of the following are cryptanalysis attacks that target hash functions? (Choose three.)

Hard
34

In the shared responsibility model for cloud computing, which of the following is typically the customer's responsibility?

Easy
35

Which TWO of the following are common attack vectors for IoT devices? (Select two)

Medium
36

An analyst captures the following output from a wireless adapter: `[00:1A:2B:3C:4D:5E] 54 Mbps WPA2 CCMP PSK`. The analyst suspects a malicious rogue AP is impersonating a legitimate network. Which of the following indicators would MOST strongly confirm a rogue AP?

Hard
37

Which of the following is a well-known attack against the MD5 hash function that allows two different inputs to produce the same hash value?

Easy
38

Which of the following tools is specifically designed for auditing cloud environments (AWS, Azure, GCP) for security misconfigurations?

Easy
39

A security analyst runs the following command: 'wget http://example.com/bucket?list-type=2' and receives a listing of objects. Which cloud misconfiguration is this MOST likely exploiting?

Medium
40

Which of the following is the PRIMARY reason that MD5 is no longer recommended for use in digital signatures?

Medium
41

An attacker performs a downgrade attack on a TLS connection, forcing the client and server to negotiate a weaker cipher suite. This attack exploits which of the following?

Medium
42

A penetration tester uses the tool 'Pacu' during an assessment. Which of the following actions is Pacu designed to perform?

Medium
43

Which THREE of the following are common attack vectors against IoT devices?

Hard
44

Which THREE of the following are valid methods to prevent a downgrade attack on TLS? (Select 3)

Hard
45

Which cryptographic algorithm is vulnerable to a birthday attack on its hash output size of 128 bits, reducing the effective security to 64 bits against collision resistance?

Hard
46

During a cloud penetration test, you discover an S3 bucket that allows listing objects. You find a file named 'config.json' that contains an IAM access key and secret key. Which of the following is the BEST next step?

Hard
47

A security team finds that a web application accepts a user-supplied URL and fetches it server-side without validation. The application runs on AWS EC2 with a metadata endpoint at 169.254.169.254. Which attack is MOST likely to succeed?

Hard
48

Which TWO of the following are characteristics of symmetric encryption? (Select two)

Easy
49

A security analyst discovers that a containerized application running in a cloud environment can access the host's file system by mounting /var/run/docker.sock inside the container. Which type of attack does this configuration enable?

Hard
50

An attacker intercepts a TLS-encrypted session and attempts to force the client and server to use a weaker cipher suite. Which type of attack is being performed?

Hard
51

A penetration tester uses the tool 'ScoutSuite' against an AWS target. Which of the following BEST describes the purpose of this tool?

Medium
52

Which THREE of the following are effective countermeasures against evil twin attacks in wireless networks? (Select THREE.)

Hard
53

During a cloud penetration test, a tester discovers an AWS S3 bucket that allows public 's3:PutObject' access. The tester uploads a file containing JavaScript that steals cookies. Which type of attack is this an example of?

Hard
54

A security analyst captures network traffic and sees multiple ARP packets with the same source MAC address but different IP addresses. Which attack is MOST likely occurring?

Easy
55

An attacker gains access to a cloud environment and attempts to move laterally by assuming an IAM role with higher privileges. Which cloud attack vector is the attacker exploiting?

Medium
56

Which cryptographic algorithm is classified as symmetric and uses a block cipher with key sizes of 128, 192, or 256 bits?

Medium
57

Which of the following cryptographic hash functions is known to be vulnerable to collision attacks and should be avoided for security applications?

Easy
58

Which THREE of the following are components of PKI (Public Key Infrastructure)?

Medium
59

Which of the following is a recommended countermeasure against WPA2 KRACK attacks?

Medium
60

A company wants to ensure that data in transit between its IoT devices and the cloud server is encrypted. Which protocol combination is BEST suited for this purpose?

Medium
61

An attacker sets up a rogue access point with the same SSID as a legitimate corporate network and broadcasts a stronger signal. Clients connect to the rogue AP. What type of attack is this?

Medium
62

A security team discovers that an attacker has been intercepting and modifying traffic between a client and server by impersonating both endpoints. Which type of cryptographic attack is this?

Medium
63

In the shared responsibility model for cloud computing, which of the following is typically the responsibility of the customer?

Easy
64

A security analyst captures WPA2 handshake packets using airodump-ng and then runs aircrack-ng with a wordlist. After several minutes, aircrack-ng reports 'KEY FOUND!' followed by a hex string. Which attack was successfully performed?

Medium
65

Which TWO of the following are examples of asymmetric cryptography? (Select 2)

Medium
66

A security analyst captures a large number of initialization vectors (IVs) on a WEP-protected network. Which tool is most commonly used to crack the WEP key using IVs?

Easy
67

An IoT device uses the MQTT protocol without TLS. An attacker on the same network subscribes to all topics and captures messages. What is the MOST significant security risk?

Medium
68

A security analyst notices that a web application's SSL/TLS certificate is issued by a CA that is not trusted by modern browsers. Which type of attack could this enable?

Medium
69

During an IoT assessment, a tester examines a smart thermostat that uses the MQTT protocol. The tester finds that the device connects to a broker without any authentication. Which of the following attacks is MOST likely to succeed?

Hard
70

A penetration tester discovers that a cloud application is vulnerable to Server-Side Request Forgery (SSRF). Which of the following is a potential impact of this vulnerability?

Hard
71

Which of the following is a hashing algorithm that produces a 160-bit (20-byte) hash value?

Easy
72

Which cryptographic algorithm is classified as symmetric and uses a block cipher with a fixed block size of 128 bits, supporting key sizes of 128, 192, and 256 bits?

Easy
73

A security analyst captures a WPA2 4-way handshake using airodump-ng. To crack the PSK, which tool would they MOST likely use next?

Medium
74

A penetration tester uses the following command to attack a WPS-enabled AP: 'reaver -i mon0 -b 00:11:22:33:44:55 -vv'. What is the primary goal of this attack?

Medium
75

A security team discovers that an S3 bucket configured for static website hosting is exposing sensitive documents. The bucket policy allows public read access. Which AWS misconfiguration is MOST likely present?

Hard
76

Which TWO of the following are symmetric encryption algorithms? (Select 2)

Medium
77

During a wireless penetration test, a tester captures the 4-way handshake between a client and WPA2-PSK access point. Which tool would the tester MOST likely use to attempt to recover the pre-shared key?

Medium
78

A security analyst is investigating a potential container escape in a Kubernetes cluster. Which THREE of the following are common indicators of a container escape?

Hard
79

Which THREE of the following are valid methods for exploiting cloud misconfigurations? (Select 3)

Hard
80

Which of the following tools is specifically designed for assessing the security of AWS environments by checking for misconfigurations in services like S3, IAM, and EC2?

Easy
81

Which of the following is a symmetric encryption algorithm that uses a block cipher with a fixed block size of 128 bits and key sizes of 128, 192, or 256 bits?

Easy
82

Which TWO of the following are symmetric encryption algorithms? (Select TWO.)

Easy
83

A security analyst captures a large number of weak initialization vectors (IVs) using airodump-ng. Which attack does this preparation indicate?

Easy
84

An analyst sees the following in a log: Client sends a request to https://victim.com/api?url=http://169.254.169.254/latest/meta-data/. This is MOST indicative of which attack?

Medium
85

Which of the following tools is specifically designed to exploit WPS vulnerabilities on wireless networks?

Medium
86

A security engineer analyzes a cloud environment and finds that an S3 bucket named 'company-backups' is configured with a bucket policy that allows 'Principal': '*' and 'Action': 's3:GetObject'. Which of the following is the MOST likely risk?

Hard
87

A security team uses ScoutSuite to assess their AWS environment. The tool reports that an S3 bucket policy allows access from any IP address. What is the MOST likely misconfiguration?

Hard
88

A cloud security engineer notices that an S3 bucket named 'company-backup' is configured to allow 's3:GetObject' access to 'Principal: *'. Which attack is this misconfiguration MOST likely to enable?

Hard
89

Which TWO of the following are symmetric encryption algorithms?

Easy
90

Which TWO of the following are common defense measures against wireless de-authentication attacks? (Select 2)

Medium
91

In an IoT environment, a researcher finds that the firmware of a smart lock can be extracted via UART and reversed to reveal hardcoded encryption keys. Which type of vulnerability is this?

Medium
92

Which cloud security assessment tool is specifically designed to audit AWS environments for misconfigurations and provides a detailed report of findings?

Easy
93

During a cloud security audit, a tool reports that an AWS IAM role has a policy allowing 'ec2:RunInstances' with a condition 'aws:SourceIp': '0.0.0.0/0'. What is the most immediate risk?

Medium
94

Which TWO of the following are common weaknesses in IoT devices that are often exploited by attackers?

Medium
95

Which TWO of the following correctly describe aspects of the shared responsibility model in cloud computing?

Easy
96

A penetration tester uses the tool 'Pacu' during an AWS security assessment. Which phase of testing is Pacu most commonly associated with?

Medium
97

During a wireless penetration test, the tester runs `airodump-ng wlan0mon` and sees numerous beacon frames from a network. The tester then sends deauthentication packets using `aireplay-ng -0 5 -a <BSSID> wlan0mon`. What is the PRIMARY purpose of this deauthentication attack?

Medium
98

A penetration tester is assessing the security of a cloud application and discovers that it is vulnerable to Server-Side Request Forgery (SSRF). Which TWO of the following are potential impacts of this vulnerability?

Medium
99

A security analyst captures a large number of unique initialization vectors (IVs) from a wireless network using airodump-ng. Which attack are they MOST likely preparing to execute?

Easy
100

A security analyst observes an SSL/TLS handshake where the client and server negotiate TLS 1.0 instead of TLS 1.2, despite the server supporting TLS 1.2. Which attack BEST describes the manipulation of the handshake to force weaker encryption?

Hard
101

Which TWO of the following attacks are specifically associated with wireless networks?

Hard
102

In a cloud environment, an attacker exploits a vulnerability in a web application to make the server send requests to internal metadata endpoints (e.g., http://169.254.169.254/latest/meta-data/). This yields IAM temporary credentials. Which attack is this?

Hard
103

A security analyst observes that a server running an IoT device management platform is sending MQTT traffic to an unexpected IP address. The analyst also notes that the device's firmware contains hardcoded credentials. Which attack vector is MOST likely being exploited?

Hard
104

An IoT device uses the MQTT protocol without any authentication or encryption. An attacker on the same network subscribes to all topics on the MQTT broker. Which of the following is the MOST effective immediate countermeasure?

Hard
105

A penetration tester is assessing an AWS environment and discovers an S3 bucket with the following bucket policy: `{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":"*","Action":"s3:GetObject","Resource":"arn:aws:s3:::example-bucket/*"}]}`. Which of the following is the MOST likely security issue?

Hard
106

During a penetration test, an analyst runs the following command: 'reaver -i wlan0mon -b 00:11:22:33:44:55 -vv'. What is the PRIMARY purpose of this command?

Medium
107

A security analyst observes the following log entry on a web server: 'GET /?url=http://169.254.169.254/latest/meta-data/ HTTP/1.1'. This request appears to originate from a compromised web application. Which cloud attack technique is being attempted?

Medium
108

Which cloud security assessment tool is specifically designed to audit AWS environments against best practices and CIS benchmarks?

Medium
109

During a penetration test, you capture the following 4-way handshake using airodump-ng. Which tool would you use to attempt a dictionary attack to recover the WPA2 passphrase?

Medium
110

In a cloud environment, which of the following is an example of a Server-Side Request Forgery (SSRF) attack?

Medium
111

Which TWO of the following tools are used for cloud security auditing or exploitation?

Medium
112

A penetration tester uses the tool Reaver to target a Wi-Fi network. What vulnerability is the tester attempting to exploit?

Medium
113

An IoT device uses MQTT for communication. An attacker intercepts MQTT packets and observes that the publish messages are not encrypted and contain plaintext sensor data. Which of the following is the BEST recommendation to secure MQTT traffic?

Medium
114

A cloud security engineer discovers that an S3 bucket named 'acme-backups' is accessible to anyone with the bucket URL. The bucket contains sensitive customer data. Which AWS shared responsibility model component does this misconfiguration primarily violate?

Medium
115

A security engineer observes the following log event: 'Certificate for www.example.com was issued by an intermediate CA that chains to a root CA not in the trusted store.' Which type of attack might this indicate?

Hard
116

A penetration tester is analyzing a captured TLS 1.3 handshake between a client and a server. The tester notices that the server's certificate is signed with RSA-PSS and the key exchange uses X25519. Which of the following statements is TRUE regarding the security of this handshake?

Medium
117

A penetration tester performs a container escape by exploiting a misconfigured capability and mounts the host filesystem. Which cloud service model is MOST directly affected?

Hard
118

A penetration tester performs a container escape from a Docker container running in a cloud environment. Which of the following is the MOST likely cause?

Hard
119

Which asymmetric encryption algorithm is based on the algebraic structure of elliptic curves over finite fields and provides equivalent security to RSA with smaller key sizes?

Easy

Frequently asked questions

What does the Advanced Topics: Wireless, Cloud, IoT, Cryptography domain cover on the CEH exam?
Identify wireless protocols, cryptographic attacks, and cloud/IoT threats by name and tool. Most important: match each scenario to the correct attack class, especially WPA3 SAE versus WPA2 PSK, and distinguish hash collisions from other cryptographic failures.
How many questions are in this domain?
This page lists all 119 Advanced Topics: Wireless, Cloud, IoT, Cryptography questions in the CEH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Advanced Topics: Wireless, Cloud, IoT, Cryptography questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-ceh EC-CEH ceh advanced topics Practice Questions