
CertNexus ITS-110 Exam Dumps - PDF Questions and Testing Engine
Latest ITS-110 Exam Dumps for Pass Guaranteed
NEW QUESTION 32
An IoT service collects massive amounts of data and the developer is encrypting the data, forcing administrative users to authenticate and be authorized. The data is being disposed of properly and on a timely basis. However, which of the following countermeasures is the developer most likely overlooking?
- A. That data is only valuable as perceived by the beholder.
- B. That data isn't valuable unless it's used as evidence for crime committed.
- C. The best practice to only collect critical data and nothing more.
- D. That private data can never be fully destroyed.
Answer: C
NEW QUESTION 33
Which of the following encryption standards should an IoT developer select in order to implement an asymmetric key pair?
- A. Triple Data Encryption Standard (3DES)
- B. Advanced Encryption Standard (AES)
- C. Elliptic curve cryptography (ECC)
- D. Temporal Key Integrity Protocol (TKIP)
Answer: C
NEW QUESTION 34
An Agile Scrum Master working on IoT solutions needs to get software released for a new IoT product. Since bugs could be found after deployment, which of the following should be part of the overall solution?
- A. A lifetime transferable warranty
- B. A money back guarantee, no questions asked
- C. Free firmware updates if the product is sent back to the manufacturer
- D. Over-the-Air (OTA) software updates
Answer: D
NEW QUESTION 35
An IoT device has many sensors on it and that sensor data is sent to the cloud. An IoT security practitioner should be sure to do which of the following in regard to that sensor data?
- A. Collect only the minimum amount of data required to perform all the business functions.
- B. The amount or type of data collected isn't important if you have a properly secured IoT device.
- C. Collect as much data as possible so as to maximize potential value of the new IoT use-case.
- D. The amount or type of data collected isn't important if you implement proper authorization controls.
Answer: A
NEW QUESTION 36
A developer is coding for an IoT product in the healthcare sector. What special care must the developer take?
- A. Apply best practices for privacy protection to minimize sensitive data exposure.
- B. Slow down product development in order to obtain FDA approval with the first submission.
- C. Rapidly complete the product so that feedback from the market can be realized sooner.
- D. Make sure the user interface looks polished so that people will pay higher prices.
Answer: A
NEW QUESTION 37
A web administrator is concerned about injection attacks. Which of the following mitigation techniques should the web administrator implement?
- A. Parameter validation
- B. Configure single sign-on (SSO)
- C. Require two-factor authentication (2FA)
- D. Require strong passwords
Answer: A
NEW QUESTION 38
A hacker is able to eavesdrop on administrative sessions to remote IoT sensors. Which of the following has most likely been misconfigured or disabled?
- A. Internet Protocol Security (IPSec)
- B. Secure Shell (SSH)
- C. Virtual private network (VPN)
- D. Telnet
Answer: A
NEW QUESTION 39
An IoT developer discovers that clients frequently fall victim to phishing attacks. What should the developer do in order to ensure that customer accounts cannot be accessed even if the customer's password has been compromised?
- A. Implement two-factor authentication (2FA)
- B. Implement account lockout policies
- C. Enable Kerberos authentication
- D. Implement Secure Lightweight Directory Access Protocol (LDAPS)
Answer: A
NEW QUESTION 40
A manufacturer wants to ensure that approved software is delivered securely and can be verified prior to installation on its IoT devices. Which of the following technologies allows the manufacturer to meet this requirement?
- A. Advanced Encryption Standard (AES)
- B. Public Key Infrastructure (PKI)
- C. Internet Protocol Security (IPsec)
- D. Generic Routing Encapsulation (GRE)
Answer: B
NEW QUESTION 41
During a brute force test on his users' passwords, the security administrator found several passwords that were cracked quickly. Which of the following passwords would have taken the longest to crack?
- A. 123my456password789
- B. GUESSmyPASSWORD
- C. Gu3$$MyP@s$w0Rd
- D. **myPASSword**
Answer: C
NEW QUESTION 42
An IoT integrator wants to deploy an IoT gateway at the Edge and have it connect to the cloud via API. In order to minimize risk, which of the following actions should the integrator take before integration?
- A. Reset the IoT gateway to factory defaults
- B. Create new credentials using a strong password
- C. Write down the default login and password
- D. Remove all logins and passwords that may exist
Answer: A
NEW QUESTION 43
An IoT systems integrator has a very old IoT gateway that doesn't offer many security features besides viewing a system configuration page via browser over HTTPS. The systems integrator can't get their modern browser to bring up the page due to a cipher suite mismatch. Which of the following must the integrator perform before the configuration page can be viewed?
- A. Downgrade the browser, as modern browsers have continued allowing connections to hosts that use only outdated cipher suites.
- B. Upgrade the browser, as older browsers have stopped allowing connections to hosts that use only outdated cipher suites.
- C. Downgrade the browser, as modern browsers have stopped allowing connections to hosts that use only outdated cipher suites.
- D. Upgrade the browser, as modern browsers have stopped allowing connections to hosts that use only outdated cipher suites.
Answer: B
NEW QUESTION 44
An IoT gateway will be brokering data on numerous northbound and southbound interfaces. A security practitioner has the data encrypted while stored on the gateway and encrypted while transmitted across the network. Should this person be concerned with privacy while the data is in use?
- A. Yes, because the data is vulnerable during processing.
- B. No, because the data is inside the CPU's secure region while being used.
- C. No, since the data is already encrypted while at rest and while in motion.
- D. Yes, because the hash wouldn't protect the integrity of the data.
Answer: A
NEW QUESTION 45
A developer needs to implement a highly secure authentication method for an IoT web portal. Which of the following authentication methods offers the highest level of identity assurance for end users?
- A. Multi-factor authentication with three factors
- B. Two-step authentication with complex passwords
- C. A hardware-based token generation device
- D. An X.509 certificate stored on a smart card
Answer: A
NEW QUESTION 46
A user grants an IoT manufacturer consent to store personally identifiable information (PII). According to the General Data Protection Regulation (GDPR), when is an organization required to delete this data?
- A. Within ninety days after collection, unless required for a legal proceeding
- B. Within sixty days after collection, unless encrypted
- C. Within thirty days of a user's written request
- D. Within seven days of being transferred to secure, long-term storage
Answer: C
NEW QUESTION 47
An IoT security administrator wants to encrypt the database used to store sensitive IoT device dat a. Which of the following algorithms should he choose?
- A. Triple Data Encryption Standard (3DES)
- B. Secure Hash Algorithm 3-512 (SHA3-512)
- C. ElGamal
- D. Rivest-Shamir-Adleman (RSA)
Answer: C
NEW QUESTION 48
Which of the following techniques protects the confidentiality of the information stored in databases?
- A. Hashing
- B. Encryption
- C. Archiving
- D. Monitoring
Answer: B
NEW QUESTION 49
A hacker is able to access privileged information via an IoT portal by modifying a SQL parameter in a URL. Which of the following BEST describes the vulnerability that allows this type of attack?
- A. Unhandled malformed URLs
- B. Unsecure direct object references
- C. Insecure HTTP session management
- D. Unvalidated redirect or forwarding
Answer: B
NEW QUESTION 50
Accompany collects and stores sensitive data from thousands of IoT devices. The company's IoT security administrator is concerned about attacks that compromise confidentiality. Which of the following attacks is the security administrator concerned about? (Choose two.)
- A. Denial of Service (DoS)
- B. Salami
- C. Inference
- D. Data diddling
- E. Aggregation
Answer: C,E
NEW QUESTION 51
......
Reliable Certified IoT Security Practitioner ITS-110 Dumps PDF Jan 15, 2023 Recently Updated Questions: https://www.vceengine.com/ITS-110-vce-test-engine.html
Pass Your CertNexus ITS-110 Exam with Correct 102 Questions and Answers: https://drive.google.com/open?id=1Rd4TQTnJp-F-Z4igc8nqQdItxzYkkDRh
