
CertNexusCertified IoT Security Practitioner (CIoTSP)
Domain 6Objective 1
Objective 6.1 Identify Common Threats Used to Exploit Unsecure Software/firmware. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 1)
Part of the 6.0 Securing Software/Firmware domain, which accounts for 10% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.
30questions here
6free pages
9concepts
10%of the exam
Questions 1–5
- 1
A vendor distributes firmware updates for its line of IP cameras. The update file is downloaded over HTTP from a vendor website, and the camera applies it without verifying any signature. An attacker performs a man-in-the-middle attack and replaces the update with malicious firmware. Which two weaknesses in the update mechanism directly enable this attack?
Select an answer first - 2
A manufacturer of smart locks uses an update mechanism where the device downloads a firmware image from a cloud server over HTTPS. The image is encrypted, but the device does not verify a digital signature. An attacker compromises the cloud server and replaces the firmware image with a malicious one. The device downloads and installs it. Which weakness in the update mechanism is most directly responsible?
Select an answer first - 3
Which security property is provided by digitally signing firmware?
Select an answer first - 4
A team is developing firmware for a new IoT sensor. The firmware processes JSON input from a web interface. The developer uses a function that concatenates user input directly into a SQL query without sanitization. The sensor has limited memory and no web application firewall. What is the most likely vulnerability?
Select an answer first - 5
Which practice is most likely to lead to the exposure of sensitive data if firmware is extracted from a device?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.