Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCertified IoT Security Practitioner (CIoTSP)

Domain 1Objective 2

Objective 1.2 Implement Countermeasures Used to Secure Web, Cloud, or Mobile Interfaces. CERTIFIED-IOT-SECURITY-PRACTITIONER Practice Questions (Page 7)

Part of the 1.0 Securing IoT Portals domain, which accounts for 29% of the CERTIFIED-IOT-SECURITY-PRACTITIONER exam.

34questions here
7free pages
9concepts
29%of the exam

Questions 31–34

  1. 31expert · hard

    A smart building's IoT portal allows facility managers to control HVAC systems. The portal has a legacy web form that is vulnerable to CSRF, and the team wants to add 2FA for all users. However, some users access the portal via a mobile app that does not support cookies. Which solution addresses both CSRF and 2FA without breaking the mobile app?

    Select an answer first
  2. 32application · medium

    A company's IoT portal is accessed by field technicians who often work in low-connectivity areas. The security policy requires strong passwords and protection against brute-force attacks, but the technicians complain that frequent password changes are disruptive. Which combination of measures best balances security and usability?

    Select an answer first
  3. 33application · medium

    A security assessment of an IoT vendor's portal found that the login response time is faster for valid usernames than for invalid ones, and the password reset page reveals whether an email is registered. Which countermeasure directly addresses both findings?

    Select an answer first
  4. 34foundation · easy

    What is the recommended way to store user passwords in a database?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CERTIFIED-IOT-SECURITY-PRACTITIONER” is a trademark of its owner, used for identification only.