
CertNexusCertified IoT Security Practitioner (CIoTSP)
Domain 6Objective 1
Objective 6.1 Identify Common Threats Used to Exploit Unsecure Software/firmware. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 4)
Part of the 6.0 Securing Software/Firmware domain, which accounts for 10% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.
30questions here
6free pages
9concepts
10%of the exam
Questions 16–20
- 16
A manufacturer of industrial controllers is designing a new product. They want to allow field technicians to update firmware via a USB port. The firmware update file is signed with the manufacturer's private key, and the bootloader verifies the signature before installing. However, the bootloader also has a 'developer mode' that can be enabled by setting a specific GPIO pin to high during boot, which skips signature verification. An attacker with physical access to a controller enables developer mode and installs malicious firmware. What is the most effective mitigation?
Select an answer first - 17
Which approach best describes a lack of end-to-end security in an IoT solution?
Select an answer first - 18
What is the primary risk of installing firmware that is not digitally signed?
Select an answer first - 19
Which risk is most directly associated with an update mechanism that downloads firmware over HTTP without any integrity verification?
Select an answer first - 20
What is the primary danger of storing cryptographic keys in plaintext within a device's file system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.