🔥 40% Off Crucial Exams Memberships — Deal ends today!

46 minutes, 25 seconds remaining!

Certified Ethical Hacker (CEH) Practice Question

During a mobile application penetration test, you are examining an Android banking app that terminates when its certificate pinning check detects your intercepting proxy. The test device is already rooted, and you prefer not to repackage or resign the APK. Which approach will most effectively let you view the app's HTTPS traffic without altering the binary?

  • Set SELinux to permissive mode with setenforce 0 before launching the application.

  • Inject a Frida script that hooks the app's certificate-validation functions and forces them to return a successful result.

  • Use iptables to transparently redirect all TCP 443 traffic to tcpdump and analyze the pcap.

  • Import the proxy's CA certificate with Android's 'Install from storage' option and rerun the application.

Certified Ethical Hacker (CEH)
Mobile Platform, IoT, and OT Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot