Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 2Objective 1

Objective 2.1 Identify Common Threats Used to Exploit Weak Authentication/authorization Schemes. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 3)

Part of the 2.0 Implementing Authentication, Authorization, and Accounting domain, which accounts for 14% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

38questions here
8free pages
11concepts
14%of the exam

Questions 11–15

  1. 11foundation · easy

    How can an attacker exploit an insecure password recovery process?

    Select an answer first
  2. 12expert · hard

    A company has implemented audit logging but does not have a process for reviewing the logs. An attacker compromises an account and accesses sensitive data. The breach is discovered months later by an external party. Which of the following is the most significant gap in the company's security posture?

    Select an answer first
  3. 13expert · hard

    A hospital's IoT medical device management system uses a single administrative account for all technicians. A technician who recently left the organization still has access because the account was not disabled. The technician used this access to view patient records and alter device settings beyond their job role. Which combination of controls would have most effectively prevented this scenario?

    Select an answer first
  4. 14application · medium

    A smart home device manufacturer's support portal allows users to reset their device passwords by answering security questions such as 'What is your mother's maiden name?'. An attacker has been observed successfully resetting several users' passwords after scraping social media profiles. Which improvement would most effectively reduce this risk?

    Select an answer first
  5. 15application · medium

    A smart city project stores sensor data in a cloud database that is publicly accessible without authentication. An attacker discovered the database and exfiltrated sensitive data. Which of the following is the most immediate and effective control to prevent this type of exposure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.