
EC-CouncilCertified Security Specialist
Domain 2Objective 4
IoT Device Security ECSS Practice Questions (Page 4)
Part of the Network Defense Systems and Monitoring domain, which makes up ~14% of our current practice bank.
44questions here
9free pages
5concepts
Questions 16–20
- 16
A company has a large number of IoT devices that are managed by different departments. The security team wants to implement a consistent security policy across all devices, but some departments resist changes that might affect device functionality. Which approach is MOST likely to succeed?
Select an answer first - 17
A facility manager wants to secure a building's access control system, which uses IoT-enabled card readers. The readers are connected to a central server via the network. The manager is concerned about unauthorized physical access if a reader is compromised. Which best practice should be implemented to mitigate this risk?
Select an answer first - 18
A security analyst is monitoring a smart building's IoT network. The analyst notices that a smart thermostat is sending data to a new IP address that is not in the allowlist. The thermostat's behavior is otherwise normal. What is the best action?
Select an answer first - 19
A hospital uses IoT infusion pumps that are critical for patient care. The pumps run on a legacy operating system with known vulnerabilities and cannot be patched without vendor approval. The network team has been asked to reduce the risk of a firmware exploit while maintaining the pumps' availability and functionality. Which approach BEST balances security and operational requirements?
Select an answer first - 20
What is a firmware exploit in the context of IoT attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.