nerdexam
EC-Council

312-50V13 · Question #217

Richard, an attacker, aimed to hack loT devices connected to a target network. In this process. Richard recorded the frequency required to share information between connected devices. After…

The correct answer is B. Replay attack. Replay Attack Explanation Why B is Correct: Richard performed a replay attack because he captured legitimate signals/commands from IoT devices and then retransmitted ("replayed") those exact signals on the same frequency to manipulate the network - without needing to decrypt or…

Submitted by ricky.ec· Mar 6, 2026IoT Hacking

Question

Richard, an attacker, aimed to hack loT devices connected to a target network. In this process. Richard recorded the frequency required to share information between connected devices. After obtaining the frequency, he captured the original data when commands were initiated by the connected devices. Once the original data were collected, he used free tools such as URH to segregate the command sequence. Subsequently, he started injecting the segregated command sequence on the same frequency into the loT network, which repeats the captured signals of the devices. What Is the type of attack performed by Richard In the above scenario?

Options

  • ASide-channel attack
  • BReplay attack
  • CCrypTanalysis attack
  • DReconnaissance attack

How the community answered

(23 responses)
  • B
    91% (21)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Replay Attack Explanation

Why B is Correct: Richard performed a replay attack because he captured legitimate signals/commands from IoT devices and then retransmitted ("replayed") those exact signals on the same frequency to manipulate the network - without needing to decrypt or understand the data. The use of URH (Universal Radio Hacker) to analyze and reinject captured wireless signals is a classic indicator of a replay attack in IoT environments.

Why the Distractors are Wrong:

  • A (Side-channel attack): This involves exploiting physical implementation characteristics (power consumption, electromagnetic emissions, timing) to extract information - not reinjecting captured signals.
  • C (Cryptanalysis attack): This focuses on breaking or analyzing encryption algorithms to reveal plaintext - Richard never attempted to crack any encryption.
  • D (Reconnaissance attack): This is purely an information-gathering phase; Richard went beyond reconnaissance by actively injecting commands into the network.

Memory Tip: Think of a replay attack like using a recorded key fob signal to unlock a car - you don't need to know how the signal works, you just capture and replay it. If the scenario mentions recording → capturing → reinjecting the same signal, it's almost always a replay attack.

Topics

#Replay attack#IoT hacking#Wireless security#Signal injection

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice