Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 2Objective 1

Objective 2.1 Identify Common Threats Used to Exploit Weak Authentication/authorization Schemes. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 7)

Part of the 2.0 Implementing Authentication, Authorization, and Accounting domain, which accounts for 14% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

38questions here
8free pages
11concepts
14%of the exam

Questions 31–35

  1. 31application · medium

    A user forgets the password to their IoT device management account. The password reset process asks for the user's date of birth and the last four digits of their social security number. An attacker who has obtained this information from a data breach successfully resets the user's password. Which of the following would be a more secure password recovery mechanism?

    Select an answer first
  2. 32foundation · easy

    Which of the following is an example of a second authentication factor?

    Select an answer first
  3. 33foundation · easy

    Why does enforcing password complexity reduce the risk of credential compromise in an IoT system?

    Select an answer first
  4. 34expert · hard

    A security team is reviewing the security posture of an IoT deployment. They notice that the system does not have any monitoring or alerting in place. Which of the following is the most significant risk resulting from this gap?

    Select an answer first
  5. 35foundation · easy

    What type of information is typically recorded in an access audit log?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.