[May 05, 2024] New CertNexus ITS-110 Dumps with Test Engine and PDF (New Questions) [Q16-Q36]

Share

[May 05, 2024] New CertNexus ITS-110  Dumps with Test Engine and PDF (New Questions)

Pass Your ITS-110 Exam Easily - Real ITS-110 Practice Dump Updated


The Internet of Things (IoT) has become one of the most transformative technologies of the 21st century. It refers to a system of interconnected devices that can communicate with each other and perform tasks without human intervention. However, the increasing use of IoT devices has also raised concerns about their security. To address these concerns, CertNexus has introduced the ITS-110 certification, which is designed to certify individuals as IoT security practitioners.

 

NEW QUESTION # 16
A compromised IoT device is initiating random connections to an attacker's server in order to exfiltrate sensitive dat a. Which type of attack is being used?

  • A. Honeypot
  • B. SSL session hijack
  • C. Man-in-the-middle (MITM)
  • D. Reverse shell

Answer: D


NEW QUESTION # 17
A network administrator is looking to implement best practices for the organization's password policy. Which of the following elements should the administrator include?

  • A. Password history checks
  • B. No use of special characters
  • C. Maximum length restriction
  • D. No password expiration

Answer: A


NEW QUESTION # 18
In order to minimize the risk of abusing access controls, which of the following is a good example of granular access control implementation?

  • A. Guest account access
  • B. Least privilege principle
  • C. System administrator access
  • D. Discretionary access control (DAC)

Answer: B


NEW QUESTION # 19
An IoT systems integrator has a very old IoT gateway that doesn't offer many security features besides viewing a system configuration page via browser over HTTPS. The systems integrator can't get their modern browser to bring up the page due to a cipher suite mismatch. Which of the following must the integrator perform before the configuration page can be viewed?

  • A. Downgrade the browser, as modern browsers have continued allowing connections to hosts that use only outdated cipher suites.
  • B. Upgrade the browser, as older browsers have stopped allowing connections to hosts that use only outdated cipher suites.
  • C. Downgrade the browser, as modern browsers have stopped allowing connections to hosts that use only outdated cipher suites.
  • D. Upgrade the browser, as modern browsers have stopped allowing connections to hosts that use only outdated cipher suites.

Answer: B


NEW QUESTION # 20
An IoT manufacturer needs to ensure that firmware flaws can be addressed even after their devices have been deployed. Which of the following methods should the manufacturer use to meet this requirement?

  • A. Ensure that a writable copy of the device's configuration is stored in flash memory
  • B. Ensure that the bootloader can be accessed remotely using Secure Shell (SSH)
  • C. Ensure that device can accept Over-the-Air (OTA) firmware updates
  • D. Ensure that ail firmware is signed using digital certificates prior to deployment

Answer: C


NEW QUESTION # 21
An IoT manufacturer discovers that hackers have injected malware into their devices' firmware updates. Which of the following methods could the manufacturer use to mitigate this risk?

  • A. Ensure that firmware updates are delivered using Internet Protocol Security (IPSec)
  • B. Ensure that firmware updates can only be installed by trusted administrators
  • C. Ensure that all firmware updates are stored using 256-bit encryption
  • D. Ensure that all firmware updates are signed with a trusted certificate

Answer: B


NEW QUESTION # 22
A hacker enters credentials into a web login page and observes the server's responses. Which of the following attacks is the hacker attempting?

  • A. Buffer overflow
  • B. Account enumeration
  • C. Spear phishing
  • D. Directory traversal

Answer: B


NEW QUESTION # 23
An IoT security administrator is concerned that someone could physically connect to his network and scan for vulnerable devices. Which of the following solutions should he install to prevent this kind of attack?

  • A. Network Access Control (NAC)
  • B. Host Intrusion Detection System (HIDS)
  • C. Media Access Control (MAC)
  • D. Network Intrusion Detection System (NIDS)

Answer: D


NEW QUESTION # 24
An IoT gateway will be brokering data on numerous northbound and southbound interfaces. A security practitioner has the data encrypted while stored on the gateway and encrypted while transmitted across the network. Should this person be concerned with privacy while the data is in use?

  • A. Yes, because the hash wouldn't protect the integrity of the data.
  • B. No, since the data is already encrypted while at rest and while in motion.
  • C. No, because the data is inside the CPU's secure region while being used.
  • D. Yes, because the data is vulnerable during processing.

Answer: D


NEW QUESTION # 25
An IoT manufacturer wants to ensure that their web-enabled cameras are secured against brute force password attacks. Which of the following technologies or protocols could they implement?

  • A. Buffer overflow prevention
  • B. Software encryption
  • C. URL filtering policies
  • D. Account lockout policies

Answer: D


NEW QUESTION # 26
An IoT device has many sensors on it and that sensor data is sent to the cloud. An IoT security practitioner should be sure to do which of the following in regard to that sensor data?

  • A. Collect only the minimum amount of data required to perform all the business functions.
  • B. The amount or type of data collected isn't important if you have a properly secured IoT device.
  • C. Collect as much data as possible so as to maximize potential value of the new IoT use-case.
  • D. The amount or type of data collected isn't important if you implement proper authorization controls.

Answer: A


NEW QUESTION # 27
Which of the following methods is an IoT portal administrator most likely to use in order to mitigate Distributed Denial of Service (DDoS) attacks?

  • A. Disable Network Address Translation Traversal (NAT-T) at the border firewall
  • B. Implement traffic scrubbers on the upstream Internet Service Provider (ISP) connection
  • C. Implement Domain Name System Security Extensions (DNSSEC) on all Internet-facing name servers
  • D. Require Internet Protocol Security (IPSec) for all inbound portal connections

Answer: B


NEW QUESTION # 28
An IoT developer wants to ensure that their cloud management portal is protected against compromised end-user credentials. Which of the following technologies should the developer implement?

  • A. An authentication policy that requires a password at initial logon, and a second password in order to access advanced features.
  • B. An authentication policy that requires a user to provide a strong password and on-demand token delivered via SMS.
  • C. An authentication policy which requires two random tokens generated by a hardware device.
  • D. An authentication policy which requires user passwords to include twelve characters, including uppercase, lowercase, and special characters.

Answer: B


NEW QUESTION # 29
A hacker is sniffing network traffic with plans to intercept user credentials and then use them to log into remote websites. Which of the following attacks could the hacker be attempting? (Choose two.)

  • A. Masquerading
  • B. Brute force
  • C. Session replay
  • D. Spear phishing
  • E. Directory traversal

Answer: B,D


NEW QUESTION # 30
An IoT developer wants to ensure all sensor to portal communications are as secure as possible and do not require any client-side configuration. Which of the following is the developer most likely to use?

  • A. Secure/Multipurpose Internet Mail Extensions (S/MIME)
  • B. IP Security (IPSec)
  • C. Public Key Infrastructure (PKI)
  • D. Virtual Private Networking (VPN)

Answer: B


NEW QUESTION # 31
If an attacker were able to gain access to a user's machine on your network, which of the following actions would she most likely take next?

  • A. Perform port scanning
  • B. Start log scrubbing
  • C. Escalate privileges
  • D. Initiate reconnaissance

Answer: D


NEW QUESTION # 32
A security practitioner wants to encrypt a large datastore. Which of the following is the BEST choice to implement?

  • A. Elliptic curve cryptography (ECC)
  • B. Diffie-Hellman (DH) algorithm
  • C. Symmetric encryption standards
  • D. Asymmetric encryption standards

Answer: C


NEW QUESTION # 33
A DevOps engineer wants to provide secure network services to an IoT/cloud solution. Which of the following countermeasures should be implemented to mitigate network attacks that can render a network useless?

  • A. Denial of Service (DoS)/Distributed Denial of Service (DDoS) mitigation
  • B. Deep Packet Inspection (DPI)
  • C. Web application firewall (WAF)
  • D. Network firewall

Answer: A


NEW QUESTION # 34
Passwords should be stored...

  • A. Inside a digital certificate.
  • B. For no more than 30 days.
  • C. As a hash value.
  • D. Only in cleartext.

Answer: C


NEW QUESTION # 35
An IoT system administrator discovers that unauthorized users are able to log onto and access data on remote IoT monitoring devices. What should the system administrator do on the remote devices in order to address this issue?

  • A. Implement URL filtering
  • B. Encrypt all locally stored data
  • C. Ensure all firmware updates have been applied
  • D. Change default passwords

Answer: D


NEW QUESTION # 36
......

DumpExam just published the CertNexus ITS-110 exam dumps!: https://www.dumpexam.com/ITS-110-valid-torrent.html

For your comfort, DumpExam provides you the convenience of free Certified IoT Security Practitioner braindumps demo: https://drive.google.com/open?id=1QJmnv_FDALQt_8opCiHIQgFA3syoj29i