Certified Internet of Things Security Practitioner Free Sample Questions

20 free sample questions232 in the full practice test

Try simulator

ITS-110 Sample Questions

  1. Question 1

    A smart utility company is deploying a large-scale mesh network of smart meters using 6LoWPAN. To prevent unauthorized devices from joining the network and injecting malicious data, which of the following is the most effective and resource-efficient security mechanism to implement at the network layer for device onboarding?

    Answer and explanation

    Correct answer: C

    Protocol for Carrying Authentication for Network Access (PANA) is a network-layer protocol specifically designed for network access authentication in IP-based networks, making it suitable for 6LoWPAN. It works with the Extensible Authentication Protocol (EAP) to provide robust authentication before a device is granted full network access. IPsec is too heavyweight for many constrained 6LoWPAN devices. MAC filtering is easily spoofed and not scalable. DTLS operates at the transport layer, not the network layer for initial access control.

  2. Question 2

    A medical device manufacturer is designing an implantable glucose monitor that transmits data to a patient's smartphone via Bluetooth Low Energy (BLE). To comply with HIPAA and protect sensitive health information, which BLE Security Mode should be mandated for the connection?

    Answer and explanation

    Correct answer: C

    For handling sensitive Protected Health Information (PHI) under HIPAA, the highest level of security is required. BLE Security Mode 1, Level 4 mandates the use of LE Secure Connections, which uses Elliptic Curve Diffie-Hellman (ECDH) key exchange for strong encryption and protects against passive eavesdropping and man-in-the-middle attacks. The lower security levels (1, 2, and 3) are not sufficient for protecting sensitive medical data.

  3. Question 3

    Multiple answers

    During a security audit of an industrial IoT deployment, a penetration tester discovers that firmware updates for programmable logic controllers (PLCs) are being delivered over-the-air (OTA) without any verification of the update source's identity. To mitigate the risk of malicious firmware injection, which TWO of the following controls are most critical to implement? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    Digital signatures provide authenticity (proving the firmware came from the manufacturer) and integrity (ensuring it wasn't altered).

    Secure boot ensures that the PLC will only load and execute firmware that has been cryptographically verified (e.g., by checking the digital signature), thus preventing unauthorized code from running.

  4. Question 4

    A security architect is designing a system for a remote environmental monitoring station powered by a solar panel and battery. The station uses a low-power wide-area network (LPWAN) to send small data packets infrequently. To protect the data packets from eavesdropping and tampering with minimal energy consumption, which protocol is most suitable?

    Answer and explanation

    Correct answer: D

    Constrained Application Protocol (CoAP) is designed for constrained devices and networks, running over UDP. Datagram Transport Layer Security (DTLS) provides security equivalent to TLS but is adapted for datagram-based protocols like UDP, making it ideal for low-power, lossy networks. This combination is energy-efficient and provides strong security. TLS over TCP, IPsec, and SSH are all too resource-intensive for this use case.

  5. Question 5

    True or False: In an IoT context, implementing Privacy by Design means that privacy considerations are addressed as a secondary feature after the main functionality has been developed and tested.

    Answer and explanation

    Correct answer: B

    The statement is false. Privacy by Design is a core principle that dictates privacy should be embedded into the design and architecture of IT systems and business practices from the very beginning of the development lifecycle, not added as an afterthought. It emphasizes proactive rather than reactive measures.

  6. Question 6

    An organization is deploying IoT sensors in a public-facing, physically accessible area. The security team is concerned about attackers connecting a device to the sensor's debug port (e.g., JTAG or UART) to extract firmware or cryptographic keys. Which of the following is the MOST effective countermeasure against this specific threat?

    Answer and explanation

    Correct answer: B

    The most direct and effective countermeasure against attacks via debug ports is to disable them completely in the final production version of the firmware. This is often done by blowing an eFuse on the microcontroller, making the change irreversible. While encryption is important, an attacker with debug access could potentially bypass it. Tamper-evident seals detect attacks but don't prevent them, and network access control is irrelevant to this physical attack vector.

  7. Question 7

    A cloud-based IoT platform uses an MQTT broker to communicate with thousands of devices. To ensure that a compromised device can only publish data to its own designated topic (e.g., devices/123/data) and subscribe only to its command topic (e.g., devices/123/commands), which security mechanism should be configured on the MQTT broker?

    Answer and explanation

    Correct answer: C

    While TLS certificates and username/password handle authentication (who the device is), they do not control authorization (what the device is allowed to do). Topic-based Access Control Lists (ACLs) are the specific mechanism used in MQTT brokers to enforce rules about which clients can publish or subscribe to specific topic patterns. This directly addresses the principle of least privilege required by the scenario.

  8. Question 8

    A company that manufactures smart home cameras is facing criticism over privacy. To demonstrate a commitment to the principle of data minimization, which action would be most effective?

    Answer and explanation

    Correct answer: B

    Data minimization is the principle of collecting and retaining only the data that is strictly necessary for a specific purpose. An 'event-only' recording mode directly applies this principle by avoiding the collection of continuous, unnecessary footage and only capturing data relevant to a security event (motion). The other options either increase data collection or relate to security and transparency, not minimization.

  9. Question 9

    A security analyst is reviewing logs from a web application firewall (WAF) that protects an IoT device management portal. The analyst observes a series of HTTP requests targeting a user profile page with the following parameter: ?user_id=123' OR '1'='1'. This pattern is indicative of which type of attack?

    Answer and explanation

    Correct answer: B

    The payload ' OR '1'='1' is a classic SQL injection technique. The attacker is attempting to manipulate the backend SQL query by appending a condition that always evaluates to true, potentially bypassing authentication or retrieving all records from a database table. XSS involves injecting client-side scripts, CSRF tricks a user into performing an unwanted action, and path traversal involves accessing files outside the intended directory.

  10. Question 10

    Multiple answers

    To prevent a power analysis side-channel attack, where an attacker measures fluctuations in a device's power consumption to deduce cryptographic operations, a hardware engineer could implement which of the following countermeasures? (Select THREE)

    Answer and explanation

    Correct answers: A, B, D

    Adding random noise makes it much harder for an attacker to isolate the small power fluctuations related to cryptographic operations.

    Constant-time algorithms ensure that operations take the same amount of time and similar power regardless of the data being processed, removing data-dependent variations an attacker could exploit.

    Blinding involves randomizing the input to a cryptographic function so that the power consumption patterns are decorrelated from the actual secret key or data.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 232 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon