
CertNexusCertified IoT Security Practitioner (CIoTSP)
Domain 2Objective 1
Objective 2.1 Identify Common Threats Used to Exploit Weak Authentication/authorization Schemes. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 6)
Part of the 2.0 Implementing Authentication, Authorization, and Accounting domain, which accounts for 14% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.
38questions here
8free pages
11concepts
14%of the exam
Questions 26–30
- 26
After a security incident, a forensic investigator needs to determine how an attacker gained access to an IoT management server. Which of the following would be most helpful in this investigation?
Select an answer first - 27
A company's IoT device management platform supports only username/password authentication. The company is considering adding two-factor authentication (2FA) to reduce the risk of credential theft. However, some legacy devices cannot support 2FA prompts. Which approach would best balance security and usability?
Select an answer first - 28
A company's IoT device admin portal has no account lockout policy. An attacker is performing a brute-force attack on a user's account. Which of the following would be the most effective control to stop this attack?
Select an answer first - 29
Which attack is most directly enabled by a user choosing a simple, easily guessable password?
Select an answer first - 30
What is the primary risk of transmitting credentials over an unencrypted protocol like HTTP?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.