Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 3Objective 1

Objective 3.1 Identify Common Threats Used to Exploit Unsecure Network Services. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 6)

Part of the 3.0 Securing Network Services domain, which accounts for 14% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

29questions here
6free pages
9concepts
14%of the exam

Questions 26–29

  1. 26application · medium

    An attacker on a local network sends packets to a smart thermostat with a spoofed source IP address of the trusted cloud server. The thermostat accepts commands from the spoofed IP and changes the temperature settings. Which attack is being performed?

    Select an answer first
  2. 27application · medium

    An attacker on the same Wi-Fi network as a smart lock sends packets with the MAC address of the authorized smartphone to the lock's access point. The lock's access point trusts the MAC address and grants access. Which attack is being performed?

    Select an answer first
  3. 28application · medium

    A security consultant is reviewing an IoT deployment that uses MQTT for messaging. The consultant finds that the MQTT broker is exposed to the internet and has no authentication. An attacker connects to the broker and publishes malicious messages to a topic that controls a smart valve. Which vulnerability is being exploited?

    Select an answer first
  4. 29application · medium

    A vulnerability researcher is testing an IoT device's network service. By sending a specially crafted packet with a payload longer than the service's input buffer expects, the researcher causes the service to crash. Which type of vulnerability is being exploited?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.