312-50 exam dumps

312-50 practice question 416 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 416

Single answer▪ IoT Hacking Methodology

During an authorized assessment of a smart building, you are asked to evaluate a Wi-Fi-enabled IP camera used in a restricted area. The camera is reachable on the internal network, hosts a web administration portal, and exposes UPnP and RTSP services. You want to follow a sound IoT hacking methodology to identify realistic attack paths without disrupting operations. Which action should you perform FIRST to most effectively guide the rest of your assessment?

  1. A

    Perform device fingerprinting and enumeration to identify the camera model, firmware version, open services, and protocols in use

  2. B

    Launch a brute-force attack against the web administration portal to quickly verify weak credentials

  3. C

    Exploit the RTSP service immediately to attempt remote code execution before the device logs rotate

  4. D

    Decompile the mobile companion application before confirming whether it is actually used with this camera

Show answer and explanation

Correct answer: A

Explanation

A practical IoT hacking methodology starts with reconnaissance and enumeration of the device and its environment. For an IP camera, that includes identifying the vendor and model, firmware version, accessible ports and services such as HTTP/HTTPS, RTSP, SSH, Telnet, UPnP, or ONVIF where applicable, and understanding how the device is administered. This information guides later phases such as credential testing, web interface analysis, firmware acquisition and analysis, service-specific vulnerability assessment, and safe exploitation. Industry best practices from penetration testing frameworks and IoT security guidance emphasize asset identification, attack surface mapping, and version enumeration before active exploitation. In real engagements, this approach reduces risk, improves accuracy, and helps tie findings to documented vulnerabilities such as vendor advisories, CVEs, and insecure default configurations.

  • A. Correct.

    Correct. In an IoT assessment, early fingerprinting and enumeration are foundational steps. Identifying the exact device model, firmware version, management interfaces, and exposed services allows the tester to map the attack surface and select safe, relevant next steps. For example, knowing whether the camera uses a known chipset, outdated firmware, default credentials, UPnP exposure, or specific RTSP implementations helps prioritize appropriate tests. This aligns with standard penetration testing methodology: reconnaissance and enumeration should guide targeted validation rather than guessing.

  • B. Incorrect.

    Incorrect. Testing for weak credentials can be valid later, especially if it is explicitly in scope and rate limits are understood, but starting with brute force is not the best first step. It may trigger account lockouts, alerts, or service degradation, and it ignores the need to first understand the device's authentication mechanisms, firmware, and management surface. A common misconception is that IoT assessments begin with password attacks because many devices have default credentials; however, disciplined methodology starts with identification and enumeration.

  • C. Incorrect.

    Incorrect. Attempting exploitation immediately is poor methodology and increases operational risk. Without first identifying the service version, firmware, and known exposure details, the tester may use an irrelevant exploit, crash the service, or miss easier and safer attack paths such as default credentials, exposed APIs, or known firmware issues. CEH-style methodology emphasizes understanding the target before exploitation.

  • D. Incorrect.

    Incorrect. Reverse engineering a mobile app can be useful in IoT testing, especially when the app exposes API endpoints, hardcoded keys, or undocumented functionality. However, doing this first is inefficient when there is no confirmation that the application is part of this camera's deployment or attack surface. Enumeration of the device itself should come before deeper analysis of supporting components unless the scenario specifically indicates the app is central to device management.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam