
CertNexusCertified IoT Security Practitioner (CIoTSP)
Domain 2Objective 2
Objective 2.2 Implement Countermeasures Used to Provide Secure Authentication, Authorization, and Accounting. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 1)
Part of the 2.0 Implementing Authentication, Authorization, and Accounting domain, which accounts for 14% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.
25questions here
5free pages
6concepts
14%of the exam
Questions 1–5
- 1
Which password policy element reduces the risk of a compromised credential being used for an extended period?
Select an answer first - 2
A hospital deploys IoT infusion pumps that are managed by a central server. Nurses need to adjust pump settings only for patients assigned to them, while biomedical engineers can adjust settings for any pump but cannot change patient assignments. The system currently grants all authenticated users full access to all pumps. Which countermeasure should be implemented to meet these requirements?
Select an answer first - 3
An IoT platform needs to restrict a maintenance technician to only view sensor data from devices in their assigned zone, while allowing facility managers to configure all devices. Which access control approach best supports this fine-grained restriction?
Select an answer first - 4
Which access control model grants permissions based on attributes such as device type, time of day, and location, rather than solely on a user's role?
Select an answer first - 5
A retail chain uses IoT cameras for security. Store managers can view live feeds, but only regional managers can export footage. The system currently allows all authenticated users to export footage. Which countermeasure should be implemented to enforce this policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.