Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 1Objective 1

Objective 1.1 Identify Common Threats Used to Compromise Unsecure Web, Cloud, or Mobile Interfaces. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 4)

Part of the 1.0 Securing IoT Portals domain, which accounts for 29% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

49questions here
10free pages
16concepts
29%of the exam

Questions 16–20

  1. 16foundation · easy

    Which of the following is a best practice for secure session management?

    Select an answer first
  2. 17application · medium

    A smart-meter portal includes a 'return to dashboard' feature that redirects users to a URL supplied in the `next` query parameter. An attacker crafts a link that redirects a logged-in user to a phishing site that mimics the portal login. Which fix should the development team implement?

    Select an answer first
  3. 18foundation · easy

    Which mitigation technique is most effective in preventing account enumeration via login error messages?

    Select an answer first
  4. 19foundation · easy

    What is the recommended way to store user passwords securely?

    Select an answer first
  5. 20foundation · easy

    A mobile app sends user credentials to the server using HTTP instead of HTTPS. What type of vulnerability does this expose?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.