Courseiva
Advanced Topics: Wireless, Cloud, IoT, CryptographymediumMultiple SelectObjective-mapped

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

Which TWO of the following are common attack vectors against IoT devices? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Default credentials left unchanged

IoT devices often have default credentials that are not changed, and they use insecure protocols like MQTT without encryption. These are common entry points for attackers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Default credentials left unchanged

    Why this is correct

    Default credentials left unchanged represent a critical attack vector because many devices, especially in IoT, ship with easily guessable or publicly known usernames and passwords. Attackers can leverage automated scanning tools and credential stuffing techniques to gain unauthorized access, often leading to full device control, data exfiltration, or recruitment into botnets without requiring complex exploits.

  • Regular firmware updates

    Why it's wrong here

    Regular firmware updates are a fundamental security best practice, not an attack vector. These updates are specifically designed to patch known vulnerabilities, fix bugs, and introduce security enhancements, thereby reducing the attack surface and mitigating potential exploitation. Failing to apply regular updates is a vulnerability, but the act of updating itself strengthens security.

  • Insecure protocols such as plaintext MQTT

    Why this is correct

    Insecure protocols such as plaintext MQTT constitute a significant attack vector due to their lack of inherent encryption and robust authentication mechanisms. This allows attackers to easily intercept and read sensitive data transmitted over the network using basic sniffing tools. Furthermore, the absence of strong authentication enables unauthorized parties to publish malicious messages, subscribe to private data streams, or manipulate device behavior, leading to data compromise or operational disruption.

  • Use of strong encryption protocols

    Why it's wrong here

    The use of strong encryption protocols, such as Transport Layer Security (TLS) or Secure Shell (SSH), is a critical security control, not an attack vector. These protocols protect data confidentiality and integrity by encrypting communications, preventing eavesdropping, man-in-the-middle attacks, and data tampering during transmission. Implementing strong encryption significantly reduces the attack surface by securing data in transit.

  • Use of certificate-based authentication

    Why it's wrong here

    Certificate-based authentication is a robust security measure designed to verify the identity of devices and users, making it a defense mechanism rather than an attack vector. By relying on trusted digital certificates issued by a Certificate Authority, this method ensures that only legitimate entities can establish secure connections. This prevents unauthorized access and impersonation, thereby strengthening overall system security.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.