Skip to content
ScopefileGet the app

Module 18Domain 7 of 9Mobile Platform, IoT, and OT Hacking

IoT and OT hacking: devices, protocols and plants

IoT and OT hacking (CEH Module 18) pairs two worlds that fail differently. IoT devices fail at scale, through defaults and neglect; OT systems fail physically, in plants where safety and uptime come first. Blueprint v5.0 gives each half the same four sub-topics: concepts, attacks, methodology and countermeasures.

Exam
312-50
Domain
7 of 9
Domain weight
10%
This file
~5%
Targets
17

The Purdue stack, level by level

Purdue reference model for industrial networks. The industrial DMZ between site operations and enterprise IT is where business traffic should stop.
Six stacked layers from physical process at level 0 up to enterprise IT at levels 4 and 5, with the industrial DMZ highlighted.Enterprise ITLevels 4-5Industrial DMZLevel 3.5Site operationsLevel 3Supervisory, HMILevel 2Basic control, PLCLevel 1Physical processLevel 0

How the two halves differ

The module shares Domain 7 (10% in blueprint v5.0 as of Oct 11, 2026) with mobile platforms. IoT means cheap, numerous, internet-reachable devices with default credentials, exposed web and cloud interfaces and unencrypted local traffic. OT means a handful of controllers that move physical things, where a reboot is an outage. The IT vs OT security comparison turns that difference into a priority order you can apply under time pressure.

IoT botnets connect this module to the denial-of-service module: hijacked cameras and routers become the flood. Classify the malware behind them the way the virus vs worm vs trojan file does, by how it spreads; self-propagation across the internet is what made those botnets so large.

IoT architecture in five layers

  1. Edge technology: sensors, actuators and their radios
  2. Access gateway: bridges local protocols to IP
  3. Internet layer: transport between the site and the cloud
  4. Middleware: device management, data handling, access control
  5. Application: the dashboards and phone apps people touch

Four communication models

Device-to-device, device-to-cloud, device-to-gateway and back-end data sharing. A home hub that translates Zigbee traffic for a cloud service is the device-to-gateway model; two smart plugs talking over Z-Wave with no hub are device-to-device.

Attack names on each side

On the IoT side the outline's names are mostly about radios and scale: rolling-code attacks that capture and replay the unlock codes of key fobs and garage remotes, Sybil attacks where one node forges many identities to distort a mesh, jamming that drowns the channel, and ransomware that locks the device rather than the data.

On the OT side the targets are the control loop itself: HMI-based attacks that show operators false values, changes to PLC logic, replay of captured control commands, and attacks aimed at the safety instrumented system. Stuxnet is the textbook case: malware that altered controller logic while operators saw normal readings.

Countermeasures that score

Inventory comes first, because you cannot protect a device nobody knows is there. Then unique credentials per device from the day it is installed, unused services such as Telnet and UPnP switched off, and vendors chosen for publishing a vulnerability disclosure process. In OT, add strict change control: nothing touches a controller's logic without a ticket and a second pair of eyes.

Protocols by range

IoT and OT protocols to recognize on sight
RangeProtocolsTypical use
ShortBLE, Zigbee, Z-Wave, NFC, RFIDWearables, home automation, badges
MediumWi-Fi HaLow, 6LoWPAN, LTE-AdvancedBuilding-wide sensor networks
LongLoRaWAN, Sigfox, NB-IoT, cellularMeters, farms, fleet tracking
Plant networkModbus, DNP3, PROFINET, BACnetControllers, substations, building systems

Smart devices and plant floors

Some targets sit on consumer gear and some on a plant floor. The option notes spell out which priority order each one follows.

Answered 0/17Hits 0

T-01

A security analyst observes unauthenticated Modbus TCP traffic interacting with holding registers on a manufacturing plant's primary programmable logic controller. What is the most critical immediate concern in this environment?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATheft of proprietary formulas is a confidentiality concern, while writing to holding registers threatens physical processes, which in OT outranks data loss.
  2. BModbus has no built-in authentication, so there are no administrative hashes being sent; the real exposure is unauthenticated write access to the controller.
  3. CLeaking staff schedules is a minor confidentiality issue compared with the risk to physical safety from an attacker who can change controller values.
  4. DCorrect: unauthenticated writes to PLC holding registers can change setpoints or actuator states, so in OT the main concern is physical manipulation that could cause safety incidents.
T-02

A smart sensor downloads updates over TLS but does not perform cryptographic signature verification before flashing the binary. Which security gap exists despite the use of encrypted transit protocols?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATLS protects the download channel, and missing signature checks do not expose private keys; the weakness is about trusting whatever firmware arrives.
  2. BCorrect: without verifying the firmware signature, the device will install any binary that reaches it, including one tampered with at the source or by a compromised update server.
  3. CTLS encryption specifically protects against eavesdropping, so passive interception of the update stream is not the gap described here.
  4. DReplay protection for the management interface is a separate control; the flaw here is that the firmware image is never checked for authenticity or integrity.
T-03

Which of the following is TRUE about the MITRE ATT&CK for ICS framework?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe phases of a penetration test come from testing methodologies such as PTES, while ATT&CK for ICS is a knowledge base of real adversary behavior, not a test plan.
  2. BCorrect: MITRE ATT&CK for ICS catalogs the tactics and techniques adversaries have used against industrial control systems, along with mitigations and detection data that defenders use.
  3. CModels that describe ICS functions and levels, such as the Purdue model, show how control systems are built, not how adversaries behave against them.
  4. DThe stages of ethical hacking describe how a tester runs an engagement, whereas ATT&CK for ICS documents what real attackers have done to industrial environments.
T-04

Which of the following methods is NOT a solution for securing communication in IoT networks?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AEncrypted protocols such as TLS or DTLS protect IoT data in transit, so they are a valid control for securing communications.
  2. BFirmware updates fix known flaws in device communication stacks and services, which makes regular updating a valid part of securing IoT networks.
  3. CDevice authentication ensures only legitimate devices can join and exchange data, which is a core control for securing IoT communications.
  4. DCorrect: hiding an SSID is not a security control, because hidden networks are still easy to discover, and it does nothing to protect the communication itself.
T-05

An incident response team determines that a fleet of connected sensors is actively participating in a Mirai-style botnet. Which immediate remediation strategy provides the most effective containment of the threat?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: isolating the infected devices and replacing default credentials stops the spread and prevents reinfection, since the 2016 Mirai botnet spread by logging in with factory-default passwords.
  2. BDetailed memory forensics on every sensor is slow and gives little value for this threat, and it does not quickly contain a botnet that is still active.
  3. CRolling back operating system software does not remove the cause, because devices with default credentials can simply be reinfected after the rollback.
  4. DReplacing all hardware is expensive and slow, and new devices would be reinfected too if their default credentials were not changed.
T-06

Which of the following is a step in the reconnaissance phase of an IoT hacking approach?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AGaining access comes after reconnaissance, when the gathered information is used to compromise a device, so it is not a reconnaissance step.
  2. BCorrect: footprinting gathers information about IoT devices, such as models, firmware, exposed services and protocols, which makes it the main activity of the reconnaissance phase.
  3. CPrivilege escalation happens after initial access, when an attacker tries to gain higher rights on a device that is already compromised.
  4. DCovering tracks is a post-exploitation activity meant to hide evidence; logging and integrity monitoring are the defensive counter to it.
T-07

A highly sensitive ICS environment is completely isolated from the corporate IP network via strict firewalls. How can an attacker physically near the facility bypass these IP-based network segmentation controls?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: radio protocols such as Bluetooth Low Energy or Zigbee on field devices are not covered by IP firewalls, so someone within radio range can reach a device without crossing the segmented network.
  2. BARP cache poisoning requires a foothold inside the local Ethernet segment, which strict isolation and firewalls are designed to keep an outsider from getting.
  3. CAn evil twin access point imitates a Wi-Fi network to trick clients, and it would not reach an isolated control network that is not using that Wi-Fi.
  4. DDNS rebinding works through a victim's browser loading external content, which needs internet-facing connectivity that an isolated ICS network does not have.
T-08

During a suspected supply-chain compromise involving industrial IoT devices, analysts must contain the threat while preserving necessary evidence. Which incident response action best balances immediate containment with root-cause investigation requirements?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AWiping devices and restoring factory defaults destroys the evidence needed to understand the supply-chain compromise, so investigation loses out to speed.
  2. BPushing patches right away changes the device state and may overwrite evidence, and it assumes the root cause is already understood.
  3. CCutting power stops execution but loses volatile evidence and can disrupt industrial processes, which makes it an unbalanced response.
  4. DCorrect: moving the devices to a quarantine network contains them while capturing full flow data preserves evidence of their behavior for root-cause analysis.
T-09

An exposed UART debug console is discovered on an industrial IoT sensor. Why is relying solely on network segmentation an insufficient mitigating control for this vulnerability?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: debug consoles are often wired into serial console servers or maintenance networks that sit outside segmentation rules, and the port can also be reached by anyone with physical access.
  2. BSegmentation is enforced by switches and firewalls, not by the sensors, so it does not add processing load to the endpoints.
  3. CA UART port is a local serial interface that works with no cloud connection at all, which is why it is reachable even on an isolated network.
  4. DSensors do not automatically broadcast their configurations across subnets; the risk from an exposed UART comes from direct or out-of-band access to the console.
T-10

To prevent unauthorized physical process manipulation from compromised internal IT workstations, which architectural control provides the MOST effective defense for securing industrial controllers?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AStateless packet filters check only addresses and ports, so a compromised workstation that is allowed to reach the controller can still send harmful commands.
  2. BEndpoint detection on IT workstations may spot some compromises, but it does not stop malicious control commands once a workstation has been taken over.
  3. CVulnerability scanning finds weaknesses periodically and can even disrupt fragile controllers; it does not block unauthorized commands in real time.
  4. DCorrect: an industrial-protocol-aware gateway inspects functions such as Modbus writes and blocks unauthorized commands to controllers, even from otherwise permitted IT hosts.
T-11

In a smart building system, various components interact to ensure efficient operation. If an attacker aims to disrupt the building's climate control through unauthorized access, which component would they target?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAn HVAC sensor only reports readings such as temperature, so tampering with one sensor has a local effect rather than giving control of the building's climate system.
  2. BCorrect: the Building Management System is the central platform that monitors and commands HVAC across the building, so it is the most valuable target and must be strongly segmented and access-controlled.
  3. CA smart thermostat controls one zone and usually reports to the BMS, so compromising it disrupts less than taking over the central management system.
  4. DA lighting control system manages lighting, not heating, ventilation or cooling, so it is not the component that runs climate control.
T-12

What type of attack focuses on extracting encryption keys or sensitive data from IoT devices by measuring power consumption patterns?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA dictionary attack tries words from a list against a password or key, and it has nothing to do with measuring a device's power consumption.
  2. BA rainbow table attack looks up precomputed hash chains to reverse password hashes, not physical signals coming from hardware.
  3. CCorrect: power analysis is a side-channel attack that infers keys from physical emissions, and it is countered with constant-time code, masking and hardware hardening.
  4. DBrute force tries every possible value directly, while this attack gets secrets from physical measurements instead of guessing.
T-13

What is a key security consideration when performing penetration testing on IoT devices?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: IoT devices have limited CPU, memory and power, so aggressive scanning or fuzzing can crash them, and tests must be scoped and paced with that in mind.
  2. BHow a device looks has no bearing on its security posture or on how to test it safely.
  3. CTesting windows are agreed in the rules of engagement, and limiting tests to business hours is a scheduling choice, not a security consideration specific to IoT.
  4. DA manufacturer's market share may affect how widespread an impact could be, but it does not change how a given device should be tested.
T-14

Which of the following statements is TRUE about IT-OT integration in manufacturing environments?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AIT-OT integration widens the attack surface by linking once-isolated control systems to business networks, so it does bring significant security risks.
  2. BIntegration usually improves efficiency by giving better visibility and data-driven optimization, which is the main business reason for doing it.
  3. CCorrect: connecting OT sensor data to IT analytics enables predictive maintenance, where likely equipment failures are spotted early from operating data.
  4. DIntegration connects IT and OT rather than isolating them; separation between them is a defensive design choice, not the result of integrating.
T-15

In the realm of IoT and OT hacking, which category of tools is utilized by an OT hacker to gather information about network traffic, including packet details, flow, and protocol usage?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACode injection inserts malicious code into a target process or application; it is an attack technique, not a way of observing network traffic.
  2. BPenetration testing is a whole assessment discipline that covers many tool categories, not the specific category used to inspect traffic and protocols.
  3. CCorrect: traffic analysis tools capture and decode packets, flows and protocol usage, and defenders use the same visibility to baseline normal OT traffic and spot anomalies.
  4. DBrute-forcing tools guess credentials or keys over and over, and they do not collect information about traffic flows or protocol usage.
T-16

Identify the malware that specifically targeted IoT devices by turning them into a botnet for launching large-scale DDoS attacks against major websites and services.

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASatori was a later variant built on Mirai's code that exploited device vulnerabilities, but it was not the botnet behind the well-known attacks on major websites.
  2. BCorrect: Mirai took over IoT devices that used default credentials and in 2016 launched record DDoS attacks, including the one on Dyn DNS that disrupted major websites.
  3. CReaper, also known as IoTroop, was an IoT botnet that spread through device vulnerabilities, but it is not the one tied to the large 2016 attacks on major services.
  4. DBrickerBot permanently disabled insecure IoT devices instead of recruiting them into a botnet, so it was not used to launch DDoS attacks.
T-17

Which of the following is NOT recommended for securing an IoT device on a smart home network?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: disabling firmware updates is the one bad practice here, because it blocks the vendor patches that close known vulnerabilities in the device.
  2. BChanging default usernames and passwords is a core IoT hardening step, since factory credentials are published and are the first thing botnets like Mirai try.
  3. CKeeping software and firmware current is recommended, because updates deliver fixes for flaws that attackers actively scan for on consumer IoT devices.
  4. DStrong, unique passwords are recommended; they resist brute-force and credential-stuffing attempts and stop one leaked password from unlocking several devices.

OT components by role

PLC
Programmable logic controller: a ruggedized computer running the logic for one machine or process step.
RTU
Remote terminal unit: collects field data and relays commands across long distances, common in pipelines and utilities.
HMI
Human-machine interface, the operator's screen. Compromise it and you can mislead the people running the process.
SCADA
Supervisory control and data acquisition: gathers data from many remote sites and lets operators send commands back.
DCS
Distributed control system: runs many tightly coupled control loops at a single site, such as a refinery.
SIS
Safety instrumented system: independent logic that drives the process to a safe state. An attack on it targets the last barrier.
Historian
Database of process values over time, often the system that feeds OT data into IT reporting.

Sources