Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 4Objective 1

Objective 4.1 Identify Common Threats Used to Exploit Unsecure Data. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 1)

Part of the 4.0 Securing Data domain, which accounts for 14% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

15questions here
3free pages
3concepts
14%of the exam

Questions 1–5

  1. 1foundation · easy

    An attacker exploits a vulnerability to gain higher-level permissions on an IoT device, allowing them to access sensitive data being processed by an application. Which type of threat is this?

    Select an answer first
  2. 2foundation · easy

    Which threat involves an attacker intercepting and potentially altering communications between two IoT devices without either device knowing?

    Select an answer first
  3. 3expert · hard

    A security auditor is reviewing the data protection measures for a medical device that stores patient records on a local hard drive and transmits them to a central server. The auditor finds that the hard drive is encrypted, but the transmission is not. The auditor also finds that the device is often left in unsecured areas. Which threat is the auditor most likely to recommend addressing first?

    Select an answer first
  4. 4application · medium

    A hospital uses a legacy medical device that transmits patient vitals to a central monitoring station over an unencrypted wireless protocol. An attacker in the parking lot uses a directional antenna to capture these transmissions and later replays them to trigger false alarms. Which threat is the attacker primarily exploiting?

    Select an answer first
  5. 5expert · hard

    A utility company needs to upgrade its smart meter network. The meters transmit usage data to a central collector over a wireless protocol. The company is considering two options: (1) using a protocol with strong encryption but no authentication, or (2) using a protocol with strong authentication but no encryption. The company's main concern is preventing attackers from injecting false usage data to reduce customers' bills. Which option should the company choose, and why?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.