CPENT · domain
Iot And OT Exploitation
Practise EC-Council Certified Penetration Testing Professional (CPENT) (CPENT) Iot And OT Exploitation practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Iot And OT Exploitation questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Iot And OT Exploitation
Iot And OT Exploitation questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Iot And OT Exploitation exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Iot And OT Exploitation questions (57)
Click any question to see the full explanation, or start a practice session above.
A hardware penetration tester is investigating an IoT device printed circuit board (PCB) to extract sensitive firmware or debug data. Which THREE of the following physical hardware interfaces are commonly targeted by testers to gain console access or read memory? (Choose THREE)
Medium2A security analyst is investigating an IoT incident where an attacker gained unauthorized access to an MQTT broker. The analyst wants to inspect the broker configuration file on a Debian-based Linux system running Eclipse Mosquitto to check if anonymous access was enabled. What is the default file path for the Mosquitto configuration file?
Medium3An ethical hacker is testing an ICS network that utilizes the IEC 60870-5-104 protocol for telecontrol equipment. The hacker wants to test whether control commands can be sent without proper authentication. Which Wireshark filter syntax should the hacker apply to isolate IEC 104 application layer frames in a capture file?
Medium4An ICS penetration tester is auditing a substation utilizing the IEC 61850 standard for electrical substation automation. The tester captures Generic Object Oriented Substation Events (GOOSE) messages on the network. Which Layer 2 Ethernet type hex value identifies GOOSE multicast frames?
Hard5A penetration tester is analyzing a smart medical pump and needs to check for open ports and running services on the embedded operating system. Using Nmap, the tester wants to perform a TCP SYN scan against the device while avoiding noisy service version detection to remain stealthy. Which Nmap flag specifies a SYN stealth scan?
Easy6An IoT firmware analyst is performing emulation of a MIPS-based router firmware binary using Firmadyne. Which TWO of the following steps or components are critical to successfully emulate and analyze the firmware image? (Choose TWO)
Hard7A pentester is analyzing an industrial control network and identifies devices communicating via EtherNet/IP (CIP). The pentester wants to enumerate explicit messaging objects and device identity data. Which Nmap script should the tester invoke?
Medium8An assessment team is analyzing an embedded Linux firmware image for an industrial IoT gateway. They have successfully extracted the filesystem using Binwalk, but they need to statically analyze the compiled binaries for potential buffer overflows and insecure function calls. Which tool is specifically designed to perform static binary analysis and identify vulnerable functions likestrcpy within the extracted filesystem?
Medium9A penetration tester is analyzing an IoT mobile companion app that communicates with a smart thermostat via BLE (Bluetooth Low Energy). Which tool can the tester use on a rooted Android device to intercept and inspect BLE GATT characteristics and descriptors?
Easy10During an IoT penetration test, an analyst discovers that a connected medical device communicates with its cloud backend using MQTT over TLS, but certificate validation is disabled in the client code. The analyst wants to perform a man-in-the-middle (MitM) attack to inspect the MQTT traffic. Which tool configured with a custom Certificate Authority (CA) is best suited to intercept this TLS-wrapped MQTT traffic?
Hard11During an IoT assessment, a tester discovers that a connected security camera runs an embedded web server with a CGI script vulnerable to OS command injection via a GET parameter. Which automated vulnerability scanner includes specific modules for detecting web-based CGI vulnerabilities and command injection?
Easy12An OT security analyst is reviewing network traffic on an industrial control system network and identifies DNP3 protocol packets. Which THREE of the following fields or functions are associated with the DNP3 protocol structure and security? (Choose THREE)
Medium13A security researcher is evaluating an industrial IoT gateway running Linux. During a filesystem audit of the extracted rootfs, the researcher finds that the '/etc/shadow' file contains weak password hashes for the root user. Which utility can the researcher use offline on their host machine to attempt password cracking via dictionary attack against the extracted hash?
Hard14During an assessment of a smart manufacturing facility, a penetration tester discovers an unauthenticated MQTT broker allowing anonymous publishing and subscription. Which TWO actions should the tester perform to validate the security risks associated with this misconfiguration? (Choose TWO)
Hard15A security consultant is performing a penetration test against an embedded IoT device that exposes an insecure bootloader and serial console. Which TWO of the following procedures can the consultant execute via the U-Boot serial prompt to compromise device security? (Choose TWO)
Hard16An ethical hacker is examining an operational technology (OT) network and needs to identify programmable logic controllers (PLCs) using their native industrial protocols. Which default TCP port should the hacker scan to discover Modbus/TCP devices?
Easy17A penetration tester is reviewing the firmware of a smart electricity meter and discovers that the bootloader is unlocked. The tester connects a USB-to-UART serial adapter to the board's exposed pins and interrupts the boot sequence to gain a root shell. Which environment variable or kernel boot parameter must the tester modify to bypass the root password authentication prompt entirely?
Medium18A security engineer is hardening an industrial SCADA environment against remote attacks. Which THREE of the following mitigation strategies are recommended best practices for securing OT networks? (Choose THREE)
Medium19An OT security engineer is conducting a vulnerability assessment on a Distributed Control System (DCS). The engineer needs to test for unauthorized firmware write capabilities on a legacy controller using the Modbus protocol. Which Modbus function code is typically associated with writing multiple holding registers, which could be abused to modify configuration parameters?
Medium20An analyst is examining the firmware of an IoT gateway and discovers a JFFS2 file system image. The analyst wants to extract the file system contents. Which tool, specifically designed for JFFS2 extraction and analysis, should the analyst run on a Linux workstation?
Medium21An auditor is reviewing an ICS network architecture and notes that a Supervisory Control and Data Acquisition (SCADA) server communicates with remote terminal units (RTUs) via DNP3 over serial-to-ethernet terminal servers. The auditor wants to test if unauthenticated DNP3 control commands can be accepted. Which default port should the auditor probe for DNP3 traffic?
Medium22During an assessment of a smart water treatment facility, an analyst notices an HTTP-based web interface running on an embedded PLC. The analyst wants to discover hidden administrative backup directories and configuration files on the web server. Which command-line tool is specifically designed for brute-forcing web server directories and files?
Easy23An engineer is conducting a security audit on a smart grid device that uses CoAP over DTLS. The engineer attempts to intercept the handshake and notices pre-shared key (PSK) cipher suites are enabled. Which OpenSSL command can the engineer use to test connecting to the DTLS service using a specific Pre-Shared Key identifier and hex-encoded key?
Hard24An IoT penetration tester is analyzing the security of a Zigbee smart lighting installation. Which TWO of the following tools or frameworks are specifically utilized when assessing 802.15.4 and Zigbee wireless security? (Choose TWO)
Hard25A penetration tester is conducting an assessment of an MQTT-based smart home ecosystem. Which THREE of the following security configuration checks should the tester perform on the MQTT broker? (Choose THREE)
Medium26A penetration tester is evaluating a smart home IoT hub and needs to extract the firmware to analyze hardcoded cryptographic keys. The device exposes a physical debugging interface on the board with clock, data, ground, and power pins. Which hardware hacking tool should the tester connect to these pins to interact with the internal flash memory and dump the firmware?
Easy27A penetration tester is evaluating an embedded IoT device that exposes a Telnet service on port 23. The tester suspects default credentials are in use. Which command-line tool can the tester use to perform a fast dictionary attack against the Telnet service using a username and password list?
Easy28An ethical hacker is evaluating a Bluetooth Low Energy (BLE) medical sensor. Which TWO of the following vulnerabilities or attack vectors are commonly associated with insecure BLE implementations in IoT devices? (Choose TWO)
Hard29An ethical hacker is performing a security assessment on an industrial facility and discovers an open Zigbee network. The hacker wants to perform active reconnaissance to map all connected nodes and routing tables. Which open-source toolset provides utilities like 'zigbee-discovery' and packet generation for IEEE 802.15.4 networks?
Medium30An IoT penetration tester is conducting a security audit of a Linux-based smart gateway. Which THREE of the following commands or file inspection techniques can the tester use on the device (or extracted rootfs) to identify privilege escalation vectors or misconfigurations? (Choose THREE)
Medium31An ICS penetration tester is auditing a manufacturing plant floor. Which TWO of the following methodologies or tools are specifically used for identifying and fingerprinting industrial control system devices across the network? (Choose TWO)
Hard32An IoT penetration tester successfully dumps the flash memory of an embedded router. The resulting binary image contains a U-Boot bootloader environment. Which command can the tester look for or attempt to inject via the serial console to override the Linux kernel boot arguments and spawn a root shell?
Medium33A penetration tester is assessing an MQTT-based industrial monitoring system where brokers communicate over unencrypted TCP ports. The tester wants to discover hidden topics that are not actively publishing data by brute-forcing topic names. Which tool natively supports MQTT fuzzing and topic discovery through automated subscription testing?
Hard34A security auditor is performing a penetration test on an operational technology (OT) network utilizing Modbus/TCP. Which THREE of the following actions can an attacker typically perform if network segmentation and firewall rules are improperly configured? (Choose THREE)
Medium35A security researcher is analyzing an embedded Linux firmware image for potential backdoors. The researcher wants to quickly scan the binary for compressed file systems, bootloader signatures, and kernel versions without extracting it. Which command-line tool is best suited for this initial identification task?
Easy36During a wireless penetration test of an industrial plant, an auditor wants to discover all active Wi-Fi access points and associated IoT wireless clients operating in the 2.4 GHz band. Which wireless auditing tool should the auditor use to monitor and dump 802.11 management frames?
Easy37A penetration tester is evaluating a smart home hub communicating via Z-Wave protocol. Which TWO of the following characteristics or security mechanisms distinguish Z-Wave from standard Wi-Fi or Zigbee implementations? (Choose TWO)
Hard38A security researcher is performing dynamic analysis of an IoT firmware binary inside an emulated MIPS environment using QEMU-user mode. When executing the binary, the application crashes with a segmentation fault due to missing dynamic library dependencies in the emulated root directory. Which environment variable must be exported to instruct QEMU where to search for the target root filesystem's shared libraries?
Hard39During a hardware penetration test of an IoT device, the tester identifies a 4-pin header on the PCB. Using a multimeter, the tester measures ground on pin 1, 3.3V on pin 4, and observes fluctuating voltages on pins 2 and 3 during boot. What hardware interface do pins 2 and 3 most likely represent?
Medium40A security analyst is performing a penetration test against a building automation system utilizing BACnet over IP. To discover BACnet devices on the local subnet without prior knowledge of their IP addresses, which specific network packet type and destination should the analyst send?
Medium41A penetration tester is assessing an industrial MQTT broker that requires client authentication but lacks Access Control Lists (ACLs). The tester successfully connects using valid credentials. Which attack technique can the tester leverage to perform denial-of-service against sensitive actuator topics?
Hard42A security consultant is performing a penetration test against a smart building HVAC system controlled by BACnet/IP. The consultant wants to discover BACnet devices and their supported object properties on the local subnet. Which utility or Python tool specifically designed for BACnet protocol assessment should the consultant use?
Medium43A penetration tester is evaluating a Zigbee-based smart home lighting network. Using a Texas Instruments CC2531 USB dongle flashed with Sniffer firmware, the tester captures over-the-air packets. To decrypt the Zigbee application layer payload in Wireshark, what critical piece of cryptographic material must the tester input into Wireshark's Zigbee decryption settings?
Hard44A security analyst is performing a security assessment on a Siemens S7-1200 PLC. Using Nmap, which NSE script should the analyst run to gather detailed device information, including rack, slot, and firmware version via the S7 communication protocol?
Hard45An ethical hacker is performing a security review of a smart energy grid employing IEC 60870-5-104. The hacker wishes to inject a forged ASDU (Application Service Data Unit) command to open a circuit breaker. Using Python, which library can the hacker use to construct and transmit raw IEC 104 application layer frames over TCP?
Hard46A penetration tester is analyzing the firmware of an IoT smart bulb extracted via a flash dump. Using Binwalk, the tester extracts the squashfs-root file system. Which command should the tester execute to search for hardcoded private RSA keys within the extracted directory?
Medium47An engineering team is hardening an Operational Technology (OT) network segment that relies on legacy SCADA protocols lacking native encryption or authentication. Which THREE compensating controls should the penetration tester recommend to mitigate risks associated with these insecure protocols? (Choose THREE)
Hard48A penetration tester is evaluating the security posture of an industrial SCADA network. Which THREE of the following operational technology (OT) vulnerabilities are most commonly found during network penetration tests of legacy control systems? (Choose THREE)
Medium49A tester is analyzing an IoT gateway that runs a web management interface. During discovery, the tester finds that the device exposes an unauthenticated API endpoint that accepts JSON input. Which command-line HTTP client should the tester use to send a custom POST request containing JSON data to test for command injection?
Easy50During an assessment of an Operational Technology (OT) network, a tester discovers a Programmable Logic Controller (PLC) using the Modbus TCP protocol. The tester needs to query holding registers to understand the operational state of the industrial process. Which default TCP port should the tester target for Modbus communications?
Easy51A penetration tester is analyzing an ARM-based IoT router firmware. The tester wants to statically analyze a compiled ELF binary named 'auth_service' to identify potential buffer overflows. Which open-source reverse engineering framework, developed by NSA, should the tester utilize to perform disassembly and decompilation of this binary?
Hard52An analyst is reviewing PCAP files captured from an ICS environment where Modbus/TCP traffic is flowing. The analyst notices cleartext commands being sent to alter coil values. Which tool can the analyst use to automatically extract Modbus registers and visualize the register state changes over time from the PCAP file?
Easy53A tester is conducting a physical security and RF assessment against a wireless building automation system operating at 433 MHz. The tester wants to capture and replay the radio frequency signal emitted by a key fob to unlock a gate. Which hardware tool is specifically designed for software-defined radio (SDR) signal capture and analysis in this frequency range?
Easy54When conducting a firmware security review of an embedded IoT device, a tester extracts the root filesystem and wants to identify potential memory corruption vulnerabilities introduced by compiler hardening settings. Which THREE security hardening flags or mechanisms should the tester verify are missing from the compiled binaries using tools like checksec? (Choose THREE)
Medium55A penetration tester is analyzing a proprietary IoT device protocol that operates over UDP. The tester has captured raw binary network traffic and wants to write a custom dissector script to parse the packet structure in Wireshark. What scripting language does Wireshark natively support for writing lightweight protocol dissectors?
Medium56An attacker is performing a man-in-the-middle attack against an industrial control network utilizing the S7comm protocol between a Siemens S7-300 PLC and an engineering station. The attacker wants to inject malicious logic into the PLC memory. Which tool can be used to craft and send malicious S7comm packets to manipulate the PLC operating mode?
Hard57A pentester is performing a security review of a smart meter that utilizes an unencrypted CoAP (Constrained Application Protocol) service running over UDP. Using Python and Scapy, the tester crafts a packet to interact with the device. Which default UDP port should the tester target for standard unencrypted CoAP communications?
HardOther domains
All CPENT exam domains
Frequently asked questions
- What does the Iot And OT Exploitation domain cover on the CPENT exam?
- Iot And OT Exploitation questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 57 Iot And OT Exploitation questions in the CPENT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Iot And OT Exploitation questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.