Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 1Objective 1

Objective 1.1 Identify Common Threats Used to Compromise Unsecure Web, Cloud, or Mobile Interfaces. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 3)

Part of the 1.0 Securing IoT Portals domain, which accounts for 29% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

49questions here
10free pages
16concepts
29%of the exam

Questions 11–15

  1. 11foundation · easy

    A cloud server is deployed with the default management port (e.g., 22 for SSH) open to the internet and verbose error messages enabled. What type of vulnerability does this represent?

    Select an answer first
  2. 12foundation · easy

    An attacker sends a URL with an overly long path to a web server, causing it to crash. What type of attack is this?

    Select an answer first
  3. 13foundation · easy

    A login form has no account lockout mechanism. What is the primary risk?

    Select an answer first
  4. 14foundation · easy

    An attacker exploits a vulnerability in a web application to make the server initiate a connection back to the attacker's machine, providing a command shell. What type of attack is this?

    Select an answer first
  5. 15application · medium

    A smart-meter vendor's customer portal allows unlimited login attempts. An attacker is observed trying thousands of password combinations for a single account. The security team wants to slow the attack without permanently locking out legitimate users. Which configuration is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.