
CertNexusCertified IoT Security Practitioner (CIoTSP)
Domain 1Objective 1
Objective 1.1 Identify Common Threats Used to Compromise Unsecure Web, Cloud, or Mobile Interfaces. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 8)
Part of the 1.0 Securing IoT Portals domain, which accounts for 29% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.
49questions here
10free pages
16concepts
29%of the exam
Questions 36–40
- 36
A smart-agriculture vendor deploys soil sensors that authenticate to the cloud using a shared API key hardcoded in the firmware. A competitor purchases one sensor, extracts the key, and uses it to send false data from thousands of spoofed devices. The vendor must prevent this while minimizing firmware update costs across a large deployed fleet. Which approach is most appropriate?
Select an answer first - 37
Which of the following is an effective alternative to account lockout for preventing brute-force attacks?
Select an answer first - 38
An attacker captures a valid session token from a user and later uses it to impersonate the user. What type of attack is this?
Select an answer first - 39
A mobile app stores user passwords in plaintext in a local database. What is the primary risk of this practice?
Select an answer first - 40
A smart-grid operator's portal authenticates users and issues a session token that remains valid for 24 hours. An attacker captures this token and replays it to perform actions as the user. Which defense is most effective at preventing the replay of a captured token?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.