Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 1Objective 1

Objective 1.1 Identify Common Threats Used to Compromise Unsecure Web, Cloud, or Mobile Interfaces. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 1)

Part of the 1.0 Securing IoT Portals domain, which accounts for 29% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

49questions here
10free pages
16concepts
29%of the exam

Questions 1–5

  1. 1foundation · easy

    An IoT edge device connects to a cloud service using a hardcoded, shared API key that is the same across all devices. What is the primary security risk?

    Select an answer first
  2. 2foundation · easy

    An attacker submits the following input into a search field: ' OR '1'='1. The application returns all records from the database. What type of attack is this?

    Select an answer first
  3. 3application · medium

    A smart-lock administrator portal allows users to change their lock PIN via a GET request. A user visits a malicious site while logged into the portal, and the site loads an image with a URL that triggers a PIN change. Which defense is most effective against this attack?

    Select an answer first
  4. 4application · medium

    A compromised smart-camera in a factory is observed making outbound connections to an unknown external IP on port 4444. The security team suspects a reverse shell. Which control is most effective at preventing this type of communication?

    Select an answer first
  5. 5foundation · easy

    Which practice is most effective in mitigating the risk of weak default credentials on IoT devices?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.