Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 2Objective 2

Objective 2.2 Implement Countermeasures Used to Provide Secure Authentication, Authorization, and Accounting. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 3)

Part of the 2.0 Implementing Authentication, Authorization, and Accounting domain, which accounts for 14% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

25questions here
5free pages
6concepts
14%of the exam

Questions 11–15

  1. 11expert · hard

    A pharmaceutical company has IoT-controlled freezers storing sensitive vaccines. The system has three user types: technicians (can view temperature and adjust settings for their assigned freezers), supervisors (can adjust any freezer but cannot change user roles), and administrators (full access including user management). The company wants to enforce least privilege while ensuring that any change to freezer settings requires re-authentication. Which combination of countermeasures best meets these requirements?

    Select an answer first
  2. 12application · medium

    A smart building management system allows facility managers to remotely unlock doors and adjust HVAC settings. The system currently requires only a single login at the start of a shift. Management is concerned that a stolen session could allow an attacker to unlock all doors. Which countermeasure should be implemented to reduce this risk?

    Select an answer first
  3. 13expert · hard

    A hospital's IoT network includes medical devices that are critical for patient care. The security team wants to be notified immediately of any failed authentication attempt, but they are concerned about alert fatigue from the high volume of benign failures (e.g., a nurse mistyping a password). Which countermeasure should be implemented to balance timely notification with reduced noise?

    Select an answer first
  4. 14expert · hard

    A financial institution uses IoT ATMs that are managed remotely. The security team wants to enforce least privilege so that only authorized technicians can perform maintenance, and they want to ensure that any maintenance action is protected against session hijacking. They also want to reduce the risk of credential theft by implementing a strong password policy. Which combination of countermeasures best meets all these requirements?

    Select an answer first
  5. 15foundation · easy

    Why is re-authentication required before performing sensitive actions, such as changing device firmware or modifying security settings?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.