[Mar 28, 2024] ITS-110 Exam Dumps - Try Best ITS-110 Exam Questions - VerifiedDumps [Q22-Q47]

Share

[Mar 28, 2024] ITS-110 Exam Dumps - Try Best ITS-110 Exam Questions - VerifiedDumps

Verified ITS-110 exam dumps Q&As with Correct 102 Questions and Answers


The ITS-110 certification is an excellent way for professionals to enhance their career prospects in the IoT security domain. Certified Internet of Things Security Practitioner certification is recognized globally and is valued by employers and organizations worldwide. Certified Internet of Things Security Practitioner certification helps professionals demonstrate their expertise in IoT security and their commitment to staying updated with the latest trends and technologies in the field.

 

NEW QUESTION # 22
An IoT security administrator wants to encrypt the database used to store sensitive IoT device dat a. Which of the following algorithms should he choose?

  • A. ElGamal
  • B. Triple Data Encryption Standard (3DES)
  • C. Rivest-Shamir-Adleman (RSA)
  • D. Secure Hash Algorithm 3-512 (SHA3-512)

Answer: A


NEW QUESTION # 23
An IoT system administrator discovers that unauthorized users are able to log onto and access data on remote IoT monitoring devices. What should the system administrator do on the remote devices in order to address this issue?

  • A. Implement URL filtering
  • B. Encrypt all locally stored data
  • C. Ensure all firmware updates have been applied
  • D. Change default passwords

Answer: D


NEW QUESTION # 24
You work for an IoT software-as-a-service (SaaS) provider. Your boss has asked you to research a way to effectively dispose of stored sensitive customer dat a. Which of the following methods should you recommend to your boss?

  • A. Crypto-shredding
  • B. Degaussing
  • C. Physical destruction
  • D. Overwriting

Answer: C


NEW QUESTION # 25
An embedded developer is about to release an IoT gateway. Which of the following precautions must be taken to minimize attacks due to physical access?

  • A. Allow access only to the software
  • B. Remove all unneeded physical ports
  • C. Allow easy access to components
  • D. Install a firewall on network ports

Answer: B


NEW QUESTION # 26
Passwords should be stored...

  • A. As a hash value.
  • B. For no more than 30 days.
  • C. Only in cleartext.
  • D. Inside a digital certificate.

Answer: A


NEW QUESTION # 27
An IoT security administrator is concerned about an external attacker using the internal device management local area network (LAN) to compromise his IoT devices. Which of the following countermeasures should the security administrator implement? (Choose three.)

  • A. Require the use of Password Authentication Protocol (PAP)
  • B. Ensure that all administrators access the management server at specific times
  • C. Ensure that all IoT management servers are running antivirus software
  • D. Create a separate management virtual LAN (VLAN)
  • E. Ensure that the Time To Live (TTL) flag for outgoing packets is set to 1
  • F. Implement 802.1X for authentication
  • G. Only allow outbound traffic from the management LAN

Answer: B,D,F


NEW QUESTION # 28
Which of the following methods is an IoT portal administrator most likely to use in order to mitigate Distributed Denial of Service (DDoS) attacks?

  • A. Implement Domain Name System Security Extensions (DNSSEC) on all Internet-facing name servers
  • B. Disable Network Address Translation Traversal (NAT-T) at the border firewall
  • C. Implement traffic scrubbers on the upstream Internet Service Provider (ISP) connection
  • D. Require Internet Protocol Security (IPSec) for all inbound portal connections

Answer: C


NEW QUESTION # 29
An IoT systems integrator has a very old IoT gateway that doesn't offer many security features besides viewing a system configuration page via browser over HTTPS. The systems integrator can't get their modern browser to bring up the page due to a cipher suite mismatch. Which of the following must the integrator perform before the configuration page can be viewed?

  • A. Upgrade the browser, as modern browsers have stopped allowing connections to hosts that use only outdated cipher suites.
  • B. Downgrade the browser, as modern browsers have continued allowing connections to hosts that use only outdated cipher suites.
  • C. Downgrade the browser, as modern browsers have stopped allowing connections to hosts that use only outdated cipher suites.
  • D. Upgrade the browser, as older browsers have stopped allowing connections to hosts that use only outdated cipher suites.

Answer: D


NEW QUESTION # 30
An IoT systems administrator wants to ensure that all data stored on remote IoT gateways is unreadable. Which of the following technologies is the administrator most likely to implement?

  • A. Internet Protocol Security (IPSec)
  • B. Triple Data Encryption Standard (3DES)
  • C. Secure Hypertext Transmission Protocol (HTTPS)
  • D. Message Digest 5 (MD5)

Answer: A


NEW QUESTION # 31
A hacker enters credentials into a web login page and observes the server's responses. Which of the following attacks is the hacker attempting?

  • A. Account enumeration
  • B. Buffer overflow
  • C. Directory traversal
  • D. Spear phishing

Answer: A


NEW QUESTION # 32
An IoT developer wants to ensure that data collected from a remotely deployed power station monitoring system is transferred securely to the cloud. Which of the following technologies should the developer consider?

  • A. Blowfish
  • B. Transport Layer Security (TLS)
  • C. Message-digest 5 (MD5)
  • D. Secure/Multipurpose Internet Mail Extensions (S/MIME)

Answer: B


NEW QUESTION # 33
An OT security practitioner wants to implement two-factor authentication (2FA). Which of the following is the least secure method to use for implementation?

  • A. Authenticator Apps for smartphones
  • B. Fast Identity Online (FIDO) Universal 2nd Factor (U2F) USB key
  • C. 2FA over Short Message Service (SMS)
  • D. Out-of-band authentication (OOBA)

Answer: C


NEW QUESTION # 34
A hacker is able to extract users' names, birth dates, height, and weight from an IoT manufacturer's user portal. Which of the following types of data has been compromised?

  • A. Personal identity information
  • B. Personal health information
  • C. Personally identifiable information
  • D. Protected health information

Answer: C


NEW QUESTION # 35
An IoT developer needs to ensure that user passwords for a smartphone app are stored securely. Which of the following methods should the developer use to meet this requirement?

  • A. Hash all passwords using Message Digest 5 (MD5)
  • B. Store all passwords in read-only memory
  • C. Encrypt all stored passwords using 128-bit Twofish
  • D. Encrypt all stored passwords using 256-bit Advanced Encryption Standard (AES-256)

Answer: D


NEW QUESTION # 36
In order to successfully perform a man-in-the-middle (MITM) attack against a secure website, which of the following could be true?

  • A. The server must be using a deprecated version of Transport Layer Security (TLS)
  • B. Client to server traffic must use Hypertext Transmission Protocol (HTTP)
  • C. The web server's X.509 certificate must be compromised
  • D. The server must be vulnerable to malformed Uniform Resource Locator (URL) injection

Answer: A


NEW QUESTION # 37
A hacker wants to record a live session between a user and a host in hopes that parts of the datastream can be used to spoof the session. Which of the following attacks is this person attempting?

  • A. Reverse shell
  • B. Fuzzing
  • C. Session replay
  • D. Bit flipping

Answer: C


NEW QUESTION # 38
What is one popular network protocol that is usually enabled by default on home routers that creates a large attack surface?

  • A. Network Address Translation (NAT)
  • B. Open virtual private network (VPN)
  • C. Universal Plug and Play (UPnP)
  • D. Domain Name System Security Extensions (DNSSEC)

Answer: C


NEW QUESTION # 39
During a brute force test on his users' passwords, the security administrator found several passwords that were cracked quickly. Which of the following passwords would have taken the longest to crack?

  • A. Gu3$$MyP@s$w0Rd
  • B. GUESSmyPASSWORD
  • C. **myPASSword**
  • D. 123my456password789

Answer: A


NEW QUESTION # 40
If a site administrator wants to improve the secure access to a cloud portal, which of the following would be the BEST countermeasure to implement?

  • A. Mandate multi-factor authentication (MFA)
  • B. Require frequent password changes
  • C. Require separation of duties
  • D. Utilize role-based access control (RBAC)

Answer: D


NEW QUESTION # 41
An IoT manufacturer wants to ensure that their web-enabled cameras are secured against brute force password attacks. Which of the following technologies or protocols could they implement?

  • A. Software encryption
  • B. Account lockout policies
  • C. Buffer overflow prevention
  • D. URL filtering policies

Answer: B


NEW QUESTION # 42
You made an online purchase of a smart watch from a software as a service (SaaS) vendor, and filled out an extensive profile that will help you track several fitness variables. The vendor will provide you with customized health insights based on your profile. With which of the following regulations should the company be compliant? (Choose three.)

  • A. Payment Card Industry Data Security Standard (PCI-DSS)
  • B. Gramm-Leach-Bliley Act (GLBA)
  • C. Federal Information Security Management Act (FISMA)
  • D. Federal Energy Regulatory Commission (FERC)
  • E. Sarbanes-Oxley (SOX)
  • F. Health Insurance Portability and Accountability Act (HIPAA)
  • G. Family Educational Rights and Privacy Act (FERPA)

Answer: A,F,G


NEW QUESTION # 43
A hacker is able to access privileged information via an IoT portal by modifying a SQL parameter in a URL. Which of the following BEST describes the vulnerability that allows this type of attack?

  • A. Unvalidated redirect or forwarding
  • B. Insecure HTTP session management
  • C. Unsecure direct object references
  • D. Unhandled malformed URLs

Answer: D


NEW QUESTION # 44
A DevOps engineer wants to provide secure network services to an IoT/cloud solution. Which of the following countermeasures should be implemented to mitigate network attacks that can render a network useless?

  • A. Web application firewall (WAF)
  • B. Network firewall
  • C. Denial of Service (DoS)/Distributed Denial of Service (DDoS) mitigation
  • D. Deep Packet Inspection (DPI)

Answer: C


NEW QUESTION # 45
An embedded engineer wants to implement security features to be sure that the IoT gateway under development will only load verified images. Which of the following countermeasures could be used to achieve this goal?

  • A. Harden the update server
  • B. Implement Over-The-Air (OTA) updates
  • C. Enforce a measured boot function
  • D. Enforce a secure boot function

Answer: D


NEW QUESTION # 46
A developer is coding for an IoT product in the healthcare sector. What special care must the developer take?

  • A. Make sure the user interface looks polished so that people will pay higher prices.
  • B. Rapidly complete the product so that feedback from the market can be realized sooner.
  • C. Apply best practices for privacy protection to minimize sensitive data exposure.
  • D. Slow down product development in order to obtain FDA approval with the first submission.

Answer: C


NEW QUESTION # 47
......

CertNexus ITS-110 Test Engine PDF - All Free Dumps: https://www.verifieddumps.com/ITS-110-valid-exam-braindumps.html

Get New ITS-110 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1QVDZmXS0qE0Q2asR43dOXZR72uLKn8mb