Courseiva

CEH · topic practice

Advanced Topics: Wireless, Cloud, IoT, Cryptography practice questions

This domain covers wireless encryption (WPA3/SAE, WPA2 flaws), cloud and IoT attack surfaces, and cryptographic weaknesses. CEH tests it through tool identification (Reaver, aircrack-ng), attack naming (collision, evil twin, rogue AP), and log or certificate analysis to classify the attack in scenario questions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Advanced Topics: Wireless, Cloud, IoT, Cryptography

What the exam tests

What to know about Advanced Topics: Wireless, Cloud, IoT, Cryptography

Identify wireless protocols, cryptographic attacks, and cloud/IoT threats by name and tool. Most important: match each scenario to the correct attack class, especially WPA3 SAE versus WPA2 PSK, and distinguish hash collisions from other cryptographic failures.

WPA3 Simultaneous Authentication of Equals (SAE) replacing WPA2 pre-shared key exchange, adding forward secrecy

WPS PIN brute-force attacks using Reaver against Wi-Fi Protected Setup enabled access points

MD5 hash collision attacks producing identical digests from two distinct inputs

Rogue or untrusted certificate chain analysis indicating man-in-the-middle or spoofed CA issuance

Watch out for

Common Advanced Topics: Wireless, Cloud, IoT, Cryptography exam traps

  • ▸Confusing WPA3 SAE with WPA2-PSK: SAE resists offline dictionary attacks, WPA2 four-way handshake capture does not.
  • ▸Mixing up hash collision with preimage attack: collisions need two differing inputs with equal digests, not reversing a hash.
  • ▸Assuming any untrusted root CA means compromise; it may be a rogue, self-signed, or misconfigured intermediate chain.

Practice set

Advanced Topics: Wireless, Cloud, IoT, Cryptography questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full wireless explanation →

A forensic analyst examines a firmware image extracted from an IoT thermostat and finds hardcoded credentials for a cloud backend. Which phase of the IoT attack lifecycle does this represent?

Question 2mediummulti select
Read the full wireless explanation →

Which TWO of the following are valid attacks against wireless networks? (Choose two.)

Question 3mediummultiple choice
Read the full wireless explanation →

A security analyst notices that after a user connects to a corporate Wi-Fi network, all HTTP traffic is redirected to a fake login page that captures credentials. The analyst suspects a rogue access point. Which attack is most likely being used to force client connections to the rogue AP?

Question 4mediummulti select
Read the full wireless explanation →

Which TWO of the following are valid cryptanalytic attacks?

Question 5hardmultiple choice
Read the full wireless explanation →

An analyst notices that a cloud application is vulnerable to Server-Side Request Forgery (SSRF). Which of the following is the MOST effective mitigation against SSRF attacks in a cloud environment?

Question 6mediummulti select
Read the full wireless explanation →

An organization is using a cloud IAM policy that allows all actions on all resources. Which TWO security issues are MOST directly related to this configuration? (Choose two.)

Question 7easymultiple choice
Read the full wireless explanation →

Which of the following cryptographic algorithms is classified as asymmetric?

Question 8hardmultiple choice
Read the full wireless explanation →

During a cloud penetration test, a tester discovers that an AWS IAM role has the following policy: `{"Effect":"Allow","Action":"*","Resource":"*"}`. This policy is attached to an EC2 instance. Which of the following attacks is the tester MOST likely to perform next?

Question 9easymultiple choice
Read the full wireless explanation →

Which of the following cryptographic algorithms is classified as asymmetric?

Question 10easymultiple choice
Read the full wireless explanation →

During a cloud penetration test, a tester discovers an S3 bucket that allows public listing and write access. Which of the following is the MOST likely misconfiguration?

Question 11hardmulti select
Read the full wireless explanation →

Which THREE of the following attacks target cryptographic weaknesses?

Question 12mediummultiple choice
Read the full wireless explanation →

A penetration tester is conducting a wireless assessment against a corporate network that uses WPA3-Enterprise with 192-bit security mode. The tester observes that the AP advertises the RSN with AKM suite 00-0F-AC:12. Which of the following attacks is MOST likely to succeed against this configuration?

Question 13hardmulti select
Read the full wireless explanation →

A security researcher is assessing an IoT deployment that uses CoAP (Constrained Application Protocol) for device management. The researcher observes that the CoAP server supports the Block-Wise transfer option and uses DTLS for security. Which two of the following attacks are MOST relevant to this CoAP implementation? (Choose two.)

Question 14easymultiple choice
Read the full wireless explanation →

A cloud security engineer is configuring a new AWS S3 bucket to store sensitive financial data. The engineer wants to ensure that the data is encrypted at rest using a key that is managed by AWS and automatically rotated annually. Which of the following should the engineer use?

Question 15easymultiple choice
Read the full wireless explanation →

A security analyst captures a large number of unique initialization vectors (IVs) from a wireless network using airodump-ng. Which attack are they MOST likely preparing to execute?

Question 16mediummultiple choice
Read the full wireless explanation →

During a penetration test, an analyst runs the following command: 'reaver -i wlan0mon -b 00:11:22:33:44:55 -vv'. What is the PRIMARY purpose of this command?

Question 17mediummultiple choice
Read the full wireless explanation →

A cloud security engineer discovers that an S3 bucket named 'acme-backups' is accessible to anyone with the bucket URL. The bucket contains sensitive customer data. Which AWS shared responsibility model component does this misconfiguration primarily violate?

Question 18hardmultiple choice
Read the full wireless explanation →

An IoT device uses the MQTT protocol without any authentication or encryption. An attacker on the same network subscribes to all topics on the MQTT broker. Which of the following is the MOST effective immediate countermeasure?

Question 19easymultiple choice
Read the full wireless explanation →

Which cryptographic algorithm is classified as symmetric and uses a block cipher with a fixed block size of 128 bits, supporting key sizes of 128, 192, and 256 bits?

Question 20mediummultiple choice
Read the full wireless explanation →

A security analyst observes the following log entry on a web server: 'GET /?url=http://169.254.169.254/latest/meta-data/ HTTP/1.1'. This request appears to originate from a compromised web application. Which cloud attack technique is being attempted?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Advanced Topics: Wireless, Cloud, IoT, Cryptography sessions

Start a Advanced Topics: Wireless, Cloud, IoT, Cryptography only practice session

Every question in these sessions is drawn from the Advanced Topics: Wireless, Cloud, IoT, Cryptography domain — nothing else.

Related practice questions

Related CEH topic practice pages

Move into related areas when this topic feels solid.

Scanning Networks and Enumeration practice questions

Scanning Networks and Enumeration practice questions for CEH.

Wireless, IoT and Cloud Security practice questions

Wireless, IoT and Cloud Security practice questions for CEH.

Vulnerability Analysis and System Hacking practice questions

Practise CEH questions linked to Vulnerability Analysis and System Hacking.

Advanced Topics: Wireless, Cloud, IoT, Cryptography practice questions

Sharpen your CEH knowledge of Advanced Topics: Wireless, Cloud, IoT, Cryptography.

Cryptography and Malware Analysis practice questions

Targeted CEH practice covering Cryptography and Malware Analysis.

Footprinting and Reconnaissance practice questions

Targeted CEH practice covering Footprinting and Reconnaissance.

Network and Web Application Attacks practice questions

Targeted CEH practice covering Network and Web Application Attacks.

Enumeration and System Hacking practice questions

Practise CEH questions linked to Enumeration and System Hacking.

Footprinting, Reconnaissance and Scanning practice questions

Sharpen your CEH knowledge of Footprinting, Reconnaissance and Scanning.

Social Engineering and Physical Security practice questions

Practise CEH questions linked to Social Engineering and Physical Security.

Malware, Social Engineering and Network Attacks practice questions

Sharpen your CEH knowledge of Malware, Social Engineering and Network Attacks.

Web Application and Injection Attacks practice questions

Sharpen your CEH knowledge of Web Application and Injection Attacks.

Frequently asked questions

What does the CEH exam test about Advanced Topics: Wireless, Cloud, IoT, Cryptography?
Identify wireless protocols, cryptographic attacks, and cloud/IoT threats by name and tool. Most important: match each scenario to the correct attack class, especially WPA3 SAE versus WPA2 PSK, and distinguish hash collisions from other cryptographic failures.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Advanced Topics: Wireless, Cloud, IoT, Cryptography questions in a focused session?
Yes — the session launcher on this page draws every question from the Advanced Topics: Wireless, Cloud, IoT, Cryptography domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CEH topics?
Use the topic links above to move to related areas, or go back to the CEH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CEH exam covers. They are not copied from any real exam or dump site.