
[Jun-2024] ITS-110 Free Sample Questions to Practice One Year Update
Download ITS-110 exam with CertNexus ITS-110 Real Exam Questions
CertNexus ITS-110 exam covers a broad range of topics related to IoT security, including the fundamentals of IoT, common IoT security threats, risk management, and compliance. It also covers the various components of IoT, such as sensors, actuators, and gateways, and how to secure them. ITS-110 exam is designed for professionals who work with IoT devices or are responsible for securing IoT networks, including IT professionals, security professionals, and IoT developers.
NEW QUESTION # 34
An IoT integrator wants to deploy an IoT gateway at the Edge and have it connect to the cloud via API. In order to minimize risk, which of the following actions should the integrator take before integration?
- A. Write down the default login and password
- B. Reset the IoT gateway to factory defaults
- C. Create new credentials using a strong password
- D. Remove all logins and passwords that may exist
Answer: B
NEW QUESTION # 35
An IoT developer needs to ensure that user passwords for a smartphone app are stored securely. Which of the following methods should the developer use to meet this requirement?
- A. Store all passwords in read-only memory
- B. Hash all passwords using Message Digest 5 (MD5)
- C. Encrypt all stored passwords using 128-bit Twofish
- D. Encrypt all stored passwords using 256-bit Advanced Encryption Standard (AES-256)
Answer: D
NEW QUESTION # 36
During a brute force test on his users' passwords, the security administrator found several passwords that were cracked quickly. Which of the following passwords would have taken the longest to crack?
- A. 123my456password789
- B. Gu3$$MyP@s$w0Rd
- C. GUESSmyPASSWORD
- D. **myPASSword**
Answer: B
NEW QUESTION # 37
A hacker is able to access privileged information via an IoT portal by modifying a SQL parameter in a URL. Which of the following BEST describes the vulnerability that allows this type of attack?
- A. Unvalidated redirect or forwarding
- B. Unsecure direct object references
- C. Unhandled malformed URLs
- D. Insecure HTTP session management
Answer: B
NEW QUESTION # 38
In order to successfully perform a man-in-the-middle (MITM) attack against a secure website, which of the following could be true?
- A. The server must be using a deprecated version of Transport Layer Security (TLS)
- B. The web server's X.509 certificate must be compromised
- C. Client to server traffic must use Hypertext Transmission Protocol (HTTP)
- D. The server must be vulnerable to malformed Uniform Resource Locator (URL) injection
Answer: A
NEW QUESTION # 39
An embedded developer is about to release an IoT gateway. Which of the following precautions must be taken to minimize attacks due to physical access?
- A. Allow easy access to components
- B. Install a firewall on network ports
- C. Allow access only to the software
- D. Remove all unneeded physical ports
Answer: D
NEW QUESTION # 40
An IoT security administrator wishes to mitigate the risk of falling victim to Distributed Denial of Service (DDoS) attacks. Which of the following mitigation strategies should the security administrator implement? (Choose two.)
- A. Require the use of X.509 digital certificates for all incoming requests
- B. Enable unused Transmission Control Protocol (TCP) service ports in order to create a honeypot
- C. Block all inbound packets originating from service ports
- D. Block all inbound packets with an internal source IP address
- E. Block the use of Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) through his perimeter firewall
Answer: A,E
NEW QUESTION # 41
Accompany collects and stores sensitive data from thousands of IoT devices. The company's IoT security administrator is concerned about attacks that compromise confidentiality. Which of the following attacks is the security administrator concerned about? (Choose two.)
- A. Inference
- B. Denial of Service (DoS)
- C. Data diddling
- D. Salami
- E. Aggregation
Answer: A,E
NEW QUESTION # 42
An IoT developer wants to ensure that their cloud management portal is protected against compromised end-user credentials. Which of the following technologies should the developer implement?
- A. An authentication policy that requires a user to provide a strong password and on-demand token delivered via SMS.
- B. An authentication policy which requires two random tokens generated by a hardware device.
- C. An authentication policy which requires user passwords to include twelve characters, including uppercase, lowercase, and special characters.
- D. An authentication policy that requires a password at initial logon, and a second password in order to access advanced features.
Answer: A
NEW QUESTION # 43
An IoT systems administrator needs to be able to detect packet injection attacks. Which of the follow methods or technologies is the administrator most likely to implement?
- A. Internet Protocol Security (IPSec) with Authentication Headers (AH)
- B. Internet Protocol Security (IPSec) with Encapsulating Security Payload (ESP)
- C. Point-to-Point Tunneling Protocol (PPTP)
- D. Layer 2 Tunneling Protocol (L2TP)
Answer: A
NEW QUESTION # 44
Which of the following attacks utilizes Media Access Control (MAC) address spoofing?
- A. Unsecured network ports
- B. Network Address Translation (NAT)
- C. Network device fuzzing
- D. Man-in-the-middle (MITM)
Answer: D
NEW QUESTION # 45
An IoT security architect wants to implement Bluetooth between two nodes. The Elliptic Curve Diffie-Hellman (ECDH) cipher suite has been identified as a requirement. Which of the following Bluetooth versions can meet this requirement?
- A. BLE v4.2
- B. Bluetooth Low Energy (BLE) v4.0
- C. Any of the BLE versions
- D. BLE v4.1
Answer: C
NEW QUESTION # 46
An IoT security practitioner should be aware of which common misconception regarding data in motion?
- A. That transmitted data is point-to-point and therefore a third party does not exist.
- B. That data can change instantly so old data is of no value.
- C. The assumption that network protocols automatically encrypt data on the fly.
- D. The assumption that all data is encrypted properly and cannot be exploited.
Answer: D
NEW QUESTION # 47
An IoT manufacturer discovers that hackers have injected malware into their devices' firmware updates. Which of the following methods could the manufacturer use to mitigate this risk?
- A. Ensure that all firmware updates are stored using 256-bit encryption
- B. Ensure that all firmware updates are signed with a trusted certificate
- C. Ensure that firmware updates can only be installed by trusted administrators
- D. Ensure that firmware updates are delivered using Internet Protocol Security (IPSec)
Answer: C
NEW QUESTION # 48
A hacker is able to access privileged information via an IoT portal by modifying a SQL parameter in a URL. Which of the following BEST describes the vulnerability that allows this type of attack?
- A. Unvalidated redirect or forwarding
- B. Unhandled malformed URLs
- C. Unsecure direct object references
- D. Insecure HTTP session management
Answer: B
NEW QUESTION # 49
Which of the following encryption standards should an IoT developer select in order to implement an asymmetric key pair?
- A. Temporal Key Integrity Protocol (TKIP)
- B. Elliptic curve cryptography (ECC)
- C. Triple Data Encryption Standard (3DES)
- D. Advanced Encryption Standard (AES)
Answer: B
NEW QUESTION # 50
A developer needs to implement a highly secure authentication method for an IoT web portal. Which of the following authentication methods offers the highest level of identity assurance for end users?
- A. An X.509 certificate stored on a smart card
- B. A hardware-based token generation device
- C. Multi-factor authentication with three factors
- D. Two-step authentication with complex passwords
Answer: C
NEW QUESTION # 51
In order to gain access to a user dashboard via an online portal, an end user must provide their username, a PIN, and a software token code. This process is known as:
- A. Type 2 authentication
- B. Two-factor authentication
- C. Biometric authentication
- D. Type 1 authentication
Answer: B
NEW QUESTION # 52
Requiring randomly generated tokens for each connection from an IoT device to the cloud can help mitigate which of the following types of attacks?
- A. Malformed URL injection
- B. Session replay
- C. SSL certificate hijacking
- D. Buffer overflow
Answer: B
NEW QUESTION # 53
Which of the following attacks would most likely be used to discover users, printers, and other objects within a network?
- A. Distributed Denial of Service (DDoS)
- B. LDAP Injection
- C. Denial of Service (DoS)
- D. SYN flood
Answer: B
NEW QUESTION # 54
Which of the following functions can be added to the authorization component of AAA to enable the principal of least privilege with flexibility?
- A. Access control list (ACL)
- B. Mandatory access control (MAC)
- C. Discretionary access control (DAC)
- D. Role-based access control (RBAC)
Answer: D
NEW QUESTION # 55
An IoT manufacturer needs to ensure that firmware flaws can be addressed even after their devices have been deployed. Which of the following methods should the manufacturer use to meet this requirement?
- A. Ensure that a writable copy of the device's configuration is stored in flash memory
- B. Ensure that device can accept Over-the-Air (OTA) firmware updates
- C. Ensure that the bootloader can be accessed remotely using Secure Shell (SSH)
- D. Ensure that ail firmware is signed using digital certificates prior to deployment
Answer: B
NEW QUESTION # 56
A web application is connected to an IoT endpoint. A hacker wants to steal data from the connection between them. Which of the following is NOT a method of attack that could be used to facilitate stealing data?
- A. Cross-Site Scripting (XSS)
- B. Cross-Site Request Forgery (CSRF)
- C. LDAP Injection
- D. SQL Injection (SQLi)
Answer: C
NEW QUESTION # 57
Which of the following methods or technologies is most likely to be used to protect an IoT portal against protocol fuzzing?
- A. Secure Hypertext Transfer Protocol (HTTPS)
- B. Next-Generation Firewall (NGFW)
- C. Public Key Infrastructure (PKI)
- D. Hash-based Message Authentication Code (HMAC)
Answer: B
NEW QUESTION # 58
......
Real exam questions are provided for Certified IoT Security Practitioner tests, which can make sure you 100% pass: https://www.itexamreview.com/ITS-110-exam-dumps.html
ITS-110 Exam with Guarantee Updated 102 Questions: https://drive.google.com/open?id=1EXUdQEutZpBGDiA3SHWXiMEumJ3vo-Yq
