ALL PASS, NO FAIL!

CEH v13 Module 17: Mobile Platforms & IoT — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 17 of 20

Mobile and IoT attack surface: app sandboxing bypass, USB debugging abuse, embedded device flaws, and firmware analysis. Exam focus: APK sideloading, USB debugging abuse, insecure local storage, and firmware extraction all appear. The thread through every question is why mobile and embedded platforms leak information desktop stacks never would.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: apktool and JADX are used for:

Answer: C — They unpack resources and decompile DEX to Java — the starting point for spotting embedded keys, weak storage, and insecure endpoints.

Question 2: A common Android application security weakness is:

Answer: B — Plaintext databases, exported components, and unencrypted HTTP calls are the classic findings in mobile app assessments.

Question 3: Jailbreaking an iOS device:

Answer: B — It voids security boundaries (code signing, sandboxing) and blocks some updates — enterprises detect it via MDM policy.

Question 4: Frida and Objection are used for:

Answer: A — They hook into a running app at runtime — bypass SSL pinning, dump data, call functions — the dynamic side of mobile pentesting (with Burp/mitmproxy for traffic).

Question 5: 'Smishing' refers to:

Answer: B — SMS has no URL preview, short codes look official, and it reaches people directly — one of the fastest-growing mobile attack vectors.

Question 6: A key capability of an enterprise MDM (Mobile Device Management) solution is:

Answer: B — MDM also distributes VPN/certificate config, blocks sideloaded apps, and detects jailbreak/root status across the fleet.

Question 7: A core security control for any mobile device is:

Answer: A — Encryption at rest (FDE/FBE) plus strong auth protects data when the device is lost, stolen, or briefly unattended.

Question 8: A frequent reason IoT devices are insecure is:

Answer: A — Constrained hardware pushes vendors to cut corners — no updates, weak auth, plaintext protocols — making IoT a perennial entry point.

Question 9: The Mirai botnet infected IoT devices primarily by:

Answer: A — Millions of cameras/routers with stock logins joined the botnet, which powered the ~1 Tbps Dyn DDoS — proof of IoT risk at scale.

Question 10: Extracting and analyzing IoT device firmware commonly uses:

Answer: D — Firmware images are carved (binwalk), unpacked, and reviewed for hardcoded credentials, insecure services, and update flaws.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Mobile Platforms & IoT practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 17 (Mobile Platforms & IoT). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 17 (Mobile Platforms & IoT) cover?

Mobile and IoT attack surface: app sandboxing bypass, USB debugging abuse, embedded device flaws, and firmware analysis. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 17 flashcards at https://cehstudy.com/ceh-v13/module-17/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Mobile Platforms & IoT quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Mobile Platforms & IoT flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 17 (Mobile Platforms & IoT). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 17 page at https://cehstudy.com/ceh-v13/module-17/. No account or sign-up required.