Certified Ethical Hacker (CEH) Practice Question

During an internal penetration test you locate several Android phones on the corporate Wi-Fi with TCP port 5555 open. Nmap indicates an unauthenticated ADB service is running, even though USB debugging is disabled by policy. You want to silently push a backdoored APK onto one device. Which mobile attack vector is the most appropriate?

  • Exploit a vulnerable WebView component to trigger a drive-by APK download when the user visits a compromised site.

  • Craft a Stagefright MMS that silently drops and installs the malicious APK on receipt.

  • Use the unauthenticated ADB service on port 5555 to connect remotely and run adb install to sideload the malicious APK.

  • Send a phishing SMS with a QR code that links to the malicious application on a fake app-store page.

Certified Ethical Hacker (CEH)
Mobile Platform, IoT, and OT Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot