Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 7Objective 1

Objective 7.1 Identify Common Threats Used to Exploit Poor Physical Security. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 1)

Part of the 7.0 Enhancing Physical Security domain, which accounts for 7% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

21questions here
5free pages
5concepts
7%of the exam

Questions 1–5

  1. 1application · medium

    A manufacturer of IoT cameras uses a plastic housing that can be opened with a standard screwdriver. The camera's firmware is stored on a removable SPI flash chip. A security researcher demonstrates that the chip can be removed and read to extract the firmware. Which threat is this demonstration most directly illustrating?

    Select an answer first
  2. 2application · medium

    A network administrator discovers that a managed switch in a wiring closet has a debug port that provides an unauthenticated shell. The switch is in a room that is shared with janitorial staff. The administrator cannot change the firmware to disable the debug port. Which action would be the most effective next step to reduce the risk of unauthorized shell access?

    Select an answer first
  3. 3foundation · easy

    An attacker connects to a device's console port and gains a command-line interface. Which threat does this represent?

    Select an answer first
  4. 4expert · hard

    A security engineer is reviewing a new IoT device that has a removable back cover and a microSD card slot. The device stores sensitive data on the microSD card. The engineer is concerned about both data theft and firmware extraction. Which control would be the most effective to protect the data on the microSD card?

    Select an answer first
  5. 5application · medium

    A hospital uses portable medical infusion pumps that store patient medication history on removable SD cards. The pumps are kept in a shared equipment room that is accessible to all clinical staff. A risk assessment identifies that an attacker could remove an SD card and later read the data on a laptop. Which control would most directly mitigate this specific risk?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.