Q: 8
John, a professional hacker, targeted CyberSol Inc., an MNC. He decided to discover the loT devices connected in the target network that are using default credentials and are vulnerable to various hijacking attacks. For this purpose, he used an automated tool to scan the target network for specific types of loT devices and detect whether they are using the default, factory-set credentials. What is the tool employed by John in the above scenario?
Options
Discussion
Option A not C. C is a management platform, but the scenario is all about scanning and finding devices with default creds. Pretty sure IoTSeeker (A) is the tool EC-Council wants here. Correct me if I'm off though.
Option A makes more sense here. IoTSeeker is built to scan for IoT devices using default credentials, which matches what the scenario describes. C is more about device management, not actively finding vulnerable endpoints. Pretty sure on this one but let me know if I missed something.
Option A C just manages not scans for creds. Platform wording is a trap here.
Isn't this question just testing for automated vuln scanning, not device management? Why does C keep showing up as a choice here?
A is the automated scanning tool for default credentials, that's its whole purpose. The others are more management platforms, not focused on vuln discovery. Pretty sure that's what EC-Council expects here based on official guide style questions, but happy to hear arguments for C.
These vendor names are so close it's annoying. Not C, it's A. IoTSeeker is literally for scanning networks to find IoT with default creds, exactly like in the scenario. AT&T IoT Platform is more about managing devices after deployment, not discovering vulnerabilities. That's how EC-Council frames these on the exam, I think. Disagree?
Looks like A, IoTSeeker. Saw similar in practice exams-it's always the scanning tool for default creds, not the management platforms.
C vs A. If the company’s using AT&T IoT Platform, it could technically automate scanning for devices and credential compliance too, especially if integrated with their management suite. I’ve seen some platforms add those features, so not fully convinced it has to be a niche tool like A every time. Anyone else read the scenario that way?
A . Don't think C is right here, AT&T IoT Platform is more for device management not scanning for default creds. The scenario calls out automated discovery and credential checking, which lines up exactly with what IoTSeeker does. Easy to get tripped up by the big vendor names, but in this context A makes the most sense.
I don’t think it’s A. C makes more sense if they're using a platform provided by AT&T for IoT management and security checks. The question mentions automated scanning, which these big IoT platforms often include by default. Could be wrong but that's my take here, let me know if I'm missing something.
Be respectful. No spam.