Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 2Objective 1

Objective 2.1 Identify Common Threats Used to Exploit Weak Authentication/authorization Schemes. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 2)

Part of the 2.0 Implementing Authentication, Authorization, and Accounting domain, which accounts for 14% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

38questions here
8free pages
11concepts
14%of the exam

Questions 6–10

  1. 6application · medium

    An IoT device manufacturer's support portal allows users to set any password, including '1234'. An attacker has been running a dictionary attack against the portal. Which of the following is the most effective way to reduce the success of this attack?

    Select an answer first
  2. 7application · medium

    A developer for an IoT device manufacturer stores API keys in the device firmware in plaintext. An attacker extracts the firmware and obtains the keys, then uses them to access the backend cloud service. Which of the following is the most effective mitigation?

    Select an answer first
  3. 8foundation · easy

    What is a common risk of an unsecured database in an IoT system?

    Select an answer first
  4. 9foundation · easy

    Which of the following is a security measure to protect a database?

    Select an answer first
  5. 10application · medium

    A developer stores database credentials in a configuration file that is included in the source code repository. The repository is accidentally made public. An attacker finds the credentials and accesses the database. Which of the following is the most effective way to prevent this type of exposure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.