
CertNexus Certified ITS-110 Dumps Questions Valid ITS-110 Materials
Current ITS-110 Exam Dumps [2023] Complete CertNexus Exam Smoothly
NEW QUESTION 27
An embedded developer is about to release an IoT gateway. Which of the following precautions must be taken to minimize attacks due to physical access?
- A. Allow access only to the software
- B. Install a firewall on network ports
- C. Allow easy access to components
- D. Remove all unneeded physical ports
Answer: D
NEW QUESTION 28
An IoT security administrator is concerned about an external attacker using the internal device management local area network (LAN) to compromise his IoT devices. Which of the following countermeasures should the security administrator implement? (Choose three.)
- A. Create a separate management virtual LAN (VLAN)
- B. Ensure that all IoT management servers are running antivirus software
- C. Ensure that the Time To Live (TTL) flag for outgoing packets is set to 1
- D. Implement 802.1X for authentication
- E. Require the use of Password Authentication Protocol (PAP)
- F. Ensure that all administrators access the management server at specific times
- G. Only allow outbound traffic from the management LAN
Answer: A,D,F
NEW QUESTION 29
You work for a multi-national IoT device vendor. Your European customers are complaining about their inability to access the personal information about them that you have collected. Which of the following regulations is your organization at risk of violating?
- A. Electronic Identification Authentication and Trust Services (elDAS)
- B. General Data Protection Regulation (GDPR)
- C. Sarbanes-Oxley (SOX)
- D. Database Service on Alternative Methods (DB-ALM)
Answer: B
NEW QUESTION 30
Which of the following policies provides the BEST protection against identity theft when data stored on an IoT portal has been compromised?
- A. Data categorization policies
- B. Data disposal policies
- C. Data retention polices
- D. Data anonymization policies
Answer: D
NEW QUESTION 31
You made an online purchase of a smart watch from a software as a service (SaaS) vendor, and filled out an extensive profile that will help you track several fitness variables. The vendor will provide you with customized health insights based on your profile. With which of the following regulations should the company be compliant? (Choose three.)
- A. Federal Energy Regulatory Commission (FERC)
- B. Sarbanes-Oxley (SOX)
- C. Health Insurance Portability and Accountability Act (HIPAA)
- D. Family Educational Rights and Privacy Act (FERPA)
- E. Gramm-Leach-Bliley Act (GLBA)
- F. Federal Information Security Management Act (FISMA)
- G. Payment Card Industry Data Security Standard (PCI-DSS)
Answer: C,D,G
NEW QUESTION 32
Network filters based on Ethernet burned-in-addresses are vulnerable to which of the following attacks?
- A. GPS spoofing
- B. Media Access Control (MAC) spoofing
- C. Buffer overflow
- D. Packet injection
Answer: B
NEW QUESTION 33
A site administrator is not enforcing strong passwords or password complexity. To which of the following types of attacks is this system probably MOST vulnerable?
- A. Dictionary attack
- B. Key logger attack
- C. Phishing attack
- D. Collision attack
Answer: A
NEW QUESTION 34
It is a new employee's first day on the job. When trying to access secured systems, he incorrectly enters his credentials multiple times. Which resulting action should take place?
- A. His account is locked.
- B. His account is deleted.
- C. He receives a new password.
- D. He notifies Human Resources.
Answer: A
NEW QUESTION 35
An embedded engineer wants to implement security features to be sure that the IoT gateway under development will only load verified images. Which of the following countermeasures could be used to achieve this goal?
- A. Enforce a secure boot function
- B. Harden the update server
- C. Enforce a measured boot function
- D. Implement Over-The-Air (OTA) updates
Answer: A
NEW QUESTION 36
A hacker wants to discover login names that may exist on a website. Which of the following responses to the login and password entries would aid in the discovery? (Choose two.)
- A. Invalid password
- B. That user does not exist
- C. Incorrect email/password combination
- D. Your login attempt was unsuccessful
- E. The username and/or password are incorrect
Answer: B,D
NEW QUESTION 37
The network administrator for an organization has read several recent articles stating that replay attacks are on the rise. Which of the following secure protocols could the administrator implement to prevent replay attacks via remote workers' VPNs? (Choose three.)
- A. Password Authentication Protocol (PAP)
- B. Layer 2 Tunneling Protocol (L2TP)
- C. Simple Network Management Protocol (SNMP)
- D. Enhanced Interior Gateway Routing Protocol (EIGRP)
- E. Challenge Handshake Authentication Protocol (CHAP)
- F. Internet Protocol Security (IPSec)
- G. Interior Gateway Routing Protocol (IGRP)
Answer: B,E,F
NEW QUESTION 38
In order to minimize the risk of abusing access controls, which of the following is a good example of granular access control implementation?
- A. Guest account access
- B. System administrator access
- C. Discretionary access control (DAC)
- D. Least privilege principle
Answer: D
NEW QUESTION 39
A hacker is able to extract users' names, birth dates, height, and weight from an IoT manufacturer's user portal. Which of the following types of data has been compromised?
- A. Protected health information
- B. Personal health information
- C. Personally identifiable information
- D. Personal identity information
Answer: C
NEW QUESTION 40
A corporation's IoT security administrator has configured his IoT endpoints to send their data directly to a database using Secure Sockets Layer (SSL)/Transport Layer Security (TLS). Which entity provides the symmetric key used to secure the data in transit?
- A. The database server
- B. The IoT endpoint
- C. The Key Distribution Center (KDC)
- D. The administrator's machine
Answer: A
NEW QUESTION 41
A hacker is able to eavesdrop on administrative sessions to remote IoT sensors. Which of the following has most likely been misconfigured or disabled?
- A. Secure Shell (SSH)
- B. Telnet
- C. Virtual private network (VPN)
- D. Internet Protocol Security (IPSec)
Answer: D
NEW QUESTION 42
An IoT device which allows unprotected shell access via console ports is most vulnerable to which of the following risks?
- A. Buffer overflow
- B. Malware installation
- C. Rainbow table attacks
- D. Directory harvesting
Answer: B
NEW QUESTION 43
A web application is connected to an IoT endpoint. A hacker wants to steal data from the connection between them. Which of the following is NOT a method of attack that could be used to facilitate stealing data?
- A. SQL Injection (SQLi)
- B. Cross-Site Scripting (XSS)
- C. LDAP Injection
- D. Cross-Site Request Forgery (CSRF)
Answer: C
NEW QUESTION 44
An IoT integrator wants to deploy an IoT gateway at the Edge and have it connect to the cloud via API. In order to minimize risk, which of the following actions should the integrator take before integration?
- A. Create new credentials using a strong password
- B. Reset the IoT gateway to factory defaults
- C. Write down the default login and password
- D. Remove all logins and passwords that may exist
Answer: B
NEW QUESTION 45
You work for a business-to-consumer (B2C) IoT device company. Your organization wishes to publish an annual report showing statistics related to the volume and variety of sensor data it collects. Which of the following should your organization do prior to using this information?
- A. Require customers to sign a subscription license
- B. Ensure all sensors are running the latest software
- C. Confirm the devices they've sold are turned on
- D. Remove any customer-specific data
Answer: D
NEW QUESTION 46
Which of the following tools or techniques is used by software developers to maintain code, but also used by hackers to maintain control of a compromised system?
- A. Stack pointer
- B. Debugger
- C. Disassembler
- D. Backdoor
Answer: D
NEW QUESTION 47
A compromised IoT device is initiating random connections to an attacker's server in order to exfiltrate sensitive dat a. Which type of attack is being used?
- A. Honeypot
- B. Reverse shell
- C. Man-in-the-middle (MITM)
- D. SSL session hijack
Answer: B
NEW QUESTION 48
A hacker enters credentials into a web login page and observes the server's responses. Which of the following attacks is the hacker attempting?
- A. Spear phishing
- B. Account enumeration
- C. Buffer overflow
- D. Directory traversal
Answer: B
NEW QUESTION 49
......
ITS-110 Premium PDF & Test Engine Files with 102 Questions & Answers: https://www.exams4sures.com/CertNexus/ITS-110-practice-exam-dumps.html
Get 100% Real ITS-110 Accurate & Verified Answers As Seen in the Real Exam!: https://drive.google.com/open?id=1X-lIjO3whIhCFqKGKCcgad7pE5OaFg4r