
Pass ITS-110 Exam in First Attempt Guaranteed 2023 Dumps!
ITS-110 Dumps Full Questions - Exam Study Guide
NEW QUESTION # 38
A hacker is able to extract users' names, birth dates, height, and weight from an IoT manufacturer's user portal. Which of the following types of data has been compromised?
- A. Personal health information
- B. Personally identifiable information
- C. Personal identity information
- D. Protected health information
Answer: B
NEW QUESTION # 39
An OT security practitioner wants to implement two-factor authentication (2FA). Which of the following is the least secure method to use for implementation?
- A. Authenticator Apps for smartphones
- B. Out-of-band authentication (OOBA)
- C. 2FA over Short Message Service (SMS)
- D. Fast Identity Online (FIDO) Universal 2nd Factor (U2F) USB key
Answer: C
NEW QUESTION # 40
A web application is connected to an IoT endpoint. A hacker wants to steal data from the connection between them. Which of the following is NOT a method of attack that could be used to facilitate stealing data?
- A. SQL Injection (SQLi)
- B. Cross-Site Request Forgery (CSRF)
- C. LDAP Injection
- D. Cross-Site Scripting (XSS)
Answer: C
NEW QUESTION # 41
A hacker enters credentials into a web login page and observes the server's responses. Which of the following attacks is the hacker attempting?
- A. Account enumeration
- B. Spear phishing
- C. Directory traversal
- D. Buffer overflow
Answer: A
NEW QUESTION # 42
An IoT gateway will be brokering data on numerous northbound and southbound interfaces. A security practitioner has the data encrypted while stored on the gateway and encrypted while transmitted across the network. Should this person be concerned with privacy while the data is in use?
- A. No, since the data is already encrypted while at rest and while in motion.
- B. Yes, because the hash wouldn't protect the integrity of the data.
- C. No, because the data is inside the CPU's secure region while being used.
- D. Yes, because the data is vulnerable during processing.
Answer: D
NEW QUESTION # 43
Web forms that contain unvalidated fields are vulnerable to which of the following attacks? (Choose two.)
- A. Ping of death
- B. Man-in-the-middle (MITM)
- C. SQL Injection (SQLi)
- D. Smurf
- E. Cross-Site Scripting (XSS)
Answer: C,E
NEW QUESTION # 44
Which of the following functions can be added to the authorization component of AAA to enable the principal of least privilege with flexibility?
- A. Access control list (ACL)
- B. Role-based access control (RBAC)
- C. Discretionary access control (DAC)
- D. Mandatory access control (MAC)
Answer: B
NEW QUESTION # 45
Which of the following attacks would most likely be used to discover users, printers, and other objects within a network?
- A. SYN flood
- B. LDAP Injection
- C. Denial of Service (DoS)
- D. Distributed Denial of Service (DDoS)
Answer: B
NEW QUESTION # 46
An IoT manufacturer wants to ensure that their web-enabled cameras are secured against brute force password attacks. Which of the following technologies or protocols could they implement?
- A. URL filtering policies
- B. Software encryption
- C. Account lockout policies
- D. Buffer overflow prevention
Answer: C
NEW QUESTION # 47
A corporation's IoT security administrator has configured his IoT endpoints to send their data directly to a database using Secure Sockets Layer (SSL)/Transport Layer Security (TLS). Which entity provides the symmetric key used to secure the data in transit?
- A. The Key Distribution Center (KDC)
- B. The database server
- C. The administrator's machine
- D. The IoT endpoint
Answer: B
NEW QUESTION # 48
A hacker is sniffing network traffic with plans to intercept user credentials and then use them to log into remote websites. Which of the following attacks could the hacker be attempting? (Choose two.)
- A. Spear phishing
- B. Directory traversal
- C. Masquerading
- D. Session replay
- E. Brute force
Answer: A,E
NEW QUESTION # 49
A manufacturer wants to ensure that approved software is delivered securely and can be verified prior to installation on its IoT devices. Which of the following technologies allows the manufacturer to meet this requirement?
- A. Internet Protocol Security (IPsec)
- B. Public Key Infrastructure (PKI)
- C. Generic Routing Encapsulation (GRE)
- D. Advanced Encryption Standard (AES)
Answer: B
NEW QUESTION # 50
An IoT security administrator is concerned that someone could physically connect to his network and scan for vulnerable devices. Which of the following solutions should he install to prevent this kind of attack?
- A. Network Access Control (NAC)
- B. Network Intrusion Detection System (NIDS)
- C. Media Access Control (MAC)
- D. Host Intrusion Detection System (HIDS)
Answer: B
NEW QUESTION # 51
An IoT software developer wants the users of her software tools to know if they have been modified by someone other than her. Which of the following tools or techniques should she use?
- A. Fuzzing
- B. Hashing
- C. Obfuscation
- D. Encryption
Answer: B
NEW QUESTION # 52
Which of the following tools or techniques is used by software developers to maintain code, but also used by hackers to maintain control of a compromised system?
- A. Backdoor
- B. Stack pointer
- C. Debugger
- D. Disassembler
Answer: A
NEW QUESTION # 53
......
Certified IoT Security Practitioner Free Certification Exam Material from Actual4dump with 102 Questions: https://www.actual4dump.com/CertNexus/ITS-110-actualtests-dumps.html
Use Real ITS-110 - 100% Cover Real Exam Questions: https://drive.google.com/open?id=1FuH7mP0FLbf82814nCYvq200OSgLQOuG