Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 1Objective 1

Objective 1.1 Identify Common Threats Used to Compromise Unsecure Web, Cloud, or Mobile Interfaces. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 5)

Part of the 1.0 Securing IoT Portals domain, which accounts for 29% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

49questions here
10free pages
16concepts
29%of the exam

Questions 21–25

  1. 21foundation · easy

    An attacker is testing a login form and notices that entering an unknown username returns a generic 'invalid credentials' message, while entering a known username returns 'invalid password'. What is the attacker able to do with this information?

    Select an answer first
  2. 22foundation · easy

    Which of the following is the best practice to protect sensitive data at rest?

    Select an answer first
  3. 23foundation · easy

    What is the best defense against malformed URL attacks?

    Select an answer first
  4. 24foundation · easy

    Which of the following is an effective defense against CSRF attacks?

    Select an answer first
  5. 25foundation · easy

    A web application locks an account after 3 failed login attempts, but the lockout lasts only 1 minute. What is the primary security weakness of this policy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.