
[Mar-2023] CertNexus ITS-110 Test Engine PDF - All Free Dumps from TestkingPass
Get New ITS-110 Certification – Valid Exam Dumps Questions
NEW QUESTION 51
An IoT security practitioner should be aware of which common misconception regarding data in motion?
- A. That data can change instantly so old data is of no value.
- B. The assumption that all data is encrypted properly and cannot be exploited.
- C. The assumption that network protocols automatically encrypt data on the fly.
- D. That transmitted data is point-to-point and therefore a third party does not exist.
Answer: B
NEW QUESTION 52
You work for an IoT software-as-a-service (SaaS) provider. Your boss has asked you to research a way to effectively dispose of stored sensitive customer dat a. Which of the following methods should you recommend to your boss?
- A. Overwriting
- B. Degaussing
- C. Physical destruction
- D. Crypto-shredding
Answer: C
NEW QUESTION 53
In order to gain access to a user dashboard via an online portal, an end user must provide their username, a PIN, and a software token code. This process is known as:
- A. Biometric authentication
- B. Type 1 authentication
- C. Type 2 authentication
- D. Two-factor authentication
Answer: D
NEW QUESTION 54
An IoT systems administrator needs to be able to detect packet injection attacks. Which of the follow methods or technologies is the administrator most likely to implement?
- A. Point-to-Point Tunneling Protocol (PPTP)
- B. Internet Protocol Security (IPSec) with Encapsulating Security Payload (ESP)
- C. Internet Protocol Security (IPSec) with Authentication Headers (AH)
- D. Layer 2 Tunneling Protocol (L2TP)
Answer: C
NEW QUESTION 55
Which of the following policies provides the BEST protection against identity theft when data stored on an IoT portal has been compromised?
- A. Data disposal policies
- B. Data anonymization policies
- C. Data categorization policies
- D. Data retention polices
Answer: B
NEW QUESTION 56
An IoT security administrator is determining which cryptographic algorithm she should use to sign her server's digital certificates. Which of the following algorithms should she choose?
- A. Diffie-Hellman (DH)
- B. Rivest Cipher 6 (RC6)
- C. Rivest-Shamir-Adleman (RSA)
- D. Rijndael
Answer: C
NEW QUESTION 57
An embedded engineer wants to implement security features to be sure that the IoT gateway under development will only load verified images. Which of the following countermeasures could be used to achieve this goal?
- A. Enforce a measured boot function
- B. Enforce a secure boot function
- C. Harden the update server
- D. Implement Over-The-Air (OTA) updates
Answer: B
NEW QUESTION 58
An IoT security architect wants to implement Bluetooth between two nodes. The Elliptic Curve Diffie-Hellman (ECDH) cipher suite has been identified as a requirement. Which of the following Bluetooth versions can meet this requirement?
- A. BLE v4.1
- B. Bluetooth Low Energy (BLE) v4.0
- C. BLE v4.2
- D. Any of the BLE versions
Answer: D
NEW QUESTION 59
A corporation's IoT security administrator has configured his IoT endpoints to send their data directly to a database using Secure Sockets Layer (SSL)/Transport Layer Security (TLS). Which entity provides the symmetric key used to secure the data in transit?
- A. The database server
- B. The administrator's machine
- C. The Key Distribution Center (KDC)
- D. The IoT endpoint
Answer: A
NEW QUESTION 60
You work for a multi-national IoT device vendor. Your European customers are complaining about their inability to access the personal information about them that you have collected. Which of the following regulations is your organization at risk of violating?
- A. Electronic Identification Authentication and Trust Services (elDAS)
- B. Database Service on Alternative Methods (DB-ALM)
- C. General Data Protection Regulation (GDPR)
- D. Sarbanes-Oxley (SOX)
Answer: C
NEW QUESTION 61
Which of the following attacks relies on the trust that a website has for a user's browser?
- A. Cross-Site Scripting (XSS)
- B. SQL Injection (SQLi)
- C. Phishing
- D. Cross-Site Request Forgery (CSRF)
Answer: D
NEW QUESTION 62
A developer needs to implement a highly secure authentication method for an IoT web portal. Which of the following authentication methods offers the highest level of identity assurance for end users?
- A. An X.509 certificate stored on a smart card
- B. A hardware-based token generation device
- C. Two-step authentication with complex passwords
- D. Multi-factor authentication with three factors
Answer: D
NEW QUESTION 63
A web administrator is concerned about injection attacks. Which of the following mitigation techniques should the web administrator implement?
- A. Parameter validation
- B. Require strong passwords
- C. Configure single sign-on (SSO)
- D. Require two-factor authentication (2FA)
Answer: A
NEW QUESTION 64
A manufacturer wants to ensure that user account information is isolated from physical attacks by storing credentials off-device. Which of the following methods or technologies best satisfies this requirement?
- A. Role-Based Access Control (RBAC)
- B. Remote Authentication Dial-In User Service (RADIUS)
- C. Border Gateway Protocol (BGP)
- D. Password Authentication Protocol (PAP)
Answer: B
NEW QUESTION 65
Requiring randomly generated tokens for each connection from an IoT device to the cloud can help mitigate which of the following types of attacks?
- A. Malformed URL injection
- B. Buffer overflow
- C. Session replay
- D. SSL certificate hijacking
Answer: C
NEW QUESTION 66
Which of the following methods or technologies is most likely to be used in order to mitigate brute force attacks?
- A. Role-based access control
- B. Secure password recovery
- C. Automated security logging
- D. Account lockout policy
Answer: D
NEW QUESTION 67
An IoT security administrator realizes that when he attempts to visit the administrative website for his devices, he is sent to a fake website. To which of the following attacks has he likely fallen victim?
- A. Buffer overflow
- B. Birthday attack
- C. Denial of Service (DoS)
- D. Domain name system (DNS) poisoning
Answer: D
NEW QUESTION 68
An OT security practitioner wants to implement two-factor authentication (2FA). Which of the following is the least secure method to use for implementation?
- A. Fast Identity Online (FIDO) Universal 2nd Factor (U2F) USB key
- B. Out-of-band authentication (OOBA)
- C. 2FA over Short Message Service (SMS)
- D. Authenticator Apps for smartphones
Answer: C
NEW QUESTION 69
......
100% Passing Guarantee - Brilliant ITS-110 Exam Questions PDF: https://www.testkingpass.com/ITS-110-testking-dumps.html
ITS-110 Dumps 2023 - NewCertNexus Exam Questions: https://drive.google.com/open?id=15plo6Nwj4sZoqYe7cauwntG_3u995Je7