Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 6Objective 1

Objective 6.1 Identify Common Threats Used to Exploit Unsecure Software/firmware. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 2)

Part of the 6.0 Securing Software/Firmware domain, which accounts for 10% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

30questions here
6free pages
9concepts
10%of the exam

Questions 6–10

  1. 6foundation · easy

    Which type of software flaw is characterized by incorrect program logic that produces unintended behavior, such as a thermostat that never turns off the heater?

    Select an answer first
  2. 7application · medium

    A city deploys thousands of smart parking sensors that run on batteries and have no network interface other than a low-power radio. The vendor discovers a critical vulnerability in the sensor firmware that could allow an attacker to spoof sensor data. The vendor releases a patch, but the sensors cannot be updated remotely. What is the most significant security concern?

    Select an answer first
  3. 8foundation · easy

    What is the primary security consequence for an IoT device that lacks over-the-air (OTA) update capabilities?

    Select an answer first
  4. 9expert · hard

    A developer is writing firmware for a new IoT device that will be deployed in a harsh environment. The device has limited memory and processing power. The developer needs to parse incoming data from a sensor. Which approach is most likely to introduce a buffer overflow vulnerability?

    Select an answer first
  5. 10foundation · easy

    Why are constrained IoT devices with limited memory and processing power often more vulnerable to attacks?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.