CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
Which TWO of the following are common weaknesses in IoT devices that are often exploited by attackers?
⚠ Common exam trap
EC-Council often tests the distinction between security controls (HSM, secure boot, signed updates) and actual vulnerabilities (default credentials, cleartext protocols), so candidates mistakenly select secure features as weaknesses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use of default or hard-coded credentials
Option C is correct because many IoT devices ship with factory-default or hard-coded credentials (e.g., admin/admin, root/root) that users never change, giving attackers trivial access via services like Telnet or SSH on ports 23/22. Option D is correct because IoT devices frequently run lightweight protocols such as MQTT, CoAP, or HTTP without TLS encryption, allowing attackers to eavesdrop on, tamper with, or inject messages on the network. Options A and B are incorrect because hardware security modules and secure boot are security hardening measures that protect keys and verify firmware integrity, not weaknesses. Option E is incorrect because firmware updates signed with cryptographic signatures are a security best practice that prevents malicious or tampered firmware from being installed, rather than a common exploitable weakness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use of hardware security modules (HSM)
Why it's wrong here
The use of Hardware Security Modules (HSMs) is a robust security control, not a weakness. HSMs are specialized physical computing devices that safeguard and manage digital keys for strong authentication and cryptographic operations, providing a tamper-resistant environment. Their implementation significantly enhances the security posture of an IoT device by protecting critical cryptographic material from unauthorized access and manipulation, thereby mitigating key compromise risks.
- ✗
Implementation of secure boot
Why it's wrong here
Implementation of secure boot is a critical security feature designed to prevent malicious software from loading during the device startup process, making it a strength, not a weakness. Secure boot ensures that only digitally signed and trusted firmware and software components are executed, verifying their integrity and authenticity before control is passed. This mechanism establishes a root of trust, protecting the device from persistent malware infections and unauthorized firmware modifications from the earliest boot stages.
- ✓
Use of default or hard-coded credentials
Why this is correct
The prevalence of default or hard-coded credentials represents a severe and common weakness in IoT devices. Many manufacturers ship devices with easily guessable default usernames and passwords (e.g., 'admin/admin', 'root/password') or embed unchangeable credentials directly into the firmware. Attackers frequently exploit these known credentials through automated scanning and brute-force attacks, gaining unauthorized access to devices, which can then be used for botnets, data exfiltration, or further network penetration.
- ✓
Use of insecure protocols such as MQTT without TLS
Why this is correct
The use of insecure protocols, such as MQTT without Transport Layer Security (TLS), is a significant vulnerability in IoT communication. MQTT, a lightweight messaging protocol, is often deployed without encryption, allowing all data transmitted between devices and brokers to be intercepted and read in plaintext by an attacker on the same network. The absence of TLS means there is no confidentiality, integrity, or authentication for the communication, making it susceptible to eavesdropping, tampering, and man-in-the-middle attacks.
- ✗
Firmware update mechanism with signed updates
Why it's wrong here
A firmware update mechanism that incorporates signed updates is a strong security measure, not a weakness. Signed updates ensure that any new firmware installed on an IoT device originates from a trusted source and has not been tampered with since its release. This cryptographic verification process prevents attackers from installing malicious or unauthorized firmware, which could otherwise compromise the device's functionality, security, or allow persistent access, thereby protecting the device's integrity and authenticity.
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.