
2023年最新のITS-110問題集レビュー専門クイズ学習材料
ITS-110テスト準備トレーニング練習試験問題 練習テスト
質問 44
A manufacturer wants to ensure that user account information is isolated from physical attacks by storing credentials off-device. Which of the following methods or technologies best satisfies this requirement?
- A. Role-Based Access Control (RBAC)
- B. Remote Authentication Dial-In User Service (RADIUS)
- C. Password Authentication Protocol (PAP)
- D. Border Gateway Protocol (BGP)
正解: B
質問 45
An IoT gateway will be brokering data on numerous northbound and southbound interfaces. A security practitioner has the data encrypted while stored on the gateway and encrypted while transmitted across the network. Should this person be concerned with privacy while the data is in use?
- A. Yes, because the data is vulnerable during processing.
- B. No, because the data is inside the CPU's secure region while being used.
- C. No, since the data is already encrypted while at rest and while in motion.
- D. Yes, because the hash wouldn't protect the integrity of the data.
正解: A
質問 46
A hacker was able to generate a trusted certificate that spoofs an IoT-enabled security camera's management portal. Which of the following is the most likely cause of this exploit?
- A. Bootloader code is stored in unsecure flash memory
- B. The portal's certificate is stored in unsecure flash memory
- C. X.509 private keys are stored in unsecure flash memory
- D. Firmware is loaded from flash using unsecure object references
正解: C
質問 47
A hacker wants to record a live session between a user and a host in hopes that parts of the datastream can be used to spoof the session. Which of the following attacks is this person attempting?
- A. Reverse shell
- B. Session replay
- C. Fuzzing
- D. Bit flipping
正解: B
質問 48
A hacker is sniffing network traffic with plans to intercept user credentials and then use them to log into remote websites. Which of the following attacks could the hacker be attempting? (Choose two.)
- A. Spear phishing
- B. Directory traversal
- C. Masquerading
- D. Session replay
- E. Brute force
正解: A,E
質問 49
Which of the following methods or technologies is most likely to be used in order to mitigate brute force attacks?
- A. Role-based access control
- B. Secure password recovery
- C. Account lockout policy
- D. Automated security logging
正解: C
質問 50
A developer needs to implement a highly secure authentication method for an IoT web portal. Which of the following authentication methods offers the highest level of identity assurance for end users?
- A. Two-step authentication with complex passwords
- B. An X.509 certificate stored on a smart card
- C. Multi-factor authentication with three factors
- D. A hardware-based token generation device
正解: C
質問 51
A hacker is able to access privileged information via an IoT portal by modifying a SQL parameter in a URL. Which of the following BEST describes the vulnerability that allows this type of attack?
- A. Unsecure direct object references
- B. Insecure HTTP session management
- C. Unhandled malformed URLs
- D. Unvalidated redirect or forwarding
正解: A
質問 52
An IoT developer has endpoints that are shipped to users in the field. Which of the following best practices must be implemented for using default passwords after delivery?
- A. Implement two-factor authentication (2FA)
- B. Apply granular role-based access
- C. Protect against account enumeration
- D. Force a password change upon initial login
正解: D
質問 53
A hacker is able to extract users' names, birth dates, height, and weight from an IoT manufacturer's user portal. Which of the following types of data has been compromised?
- A. Protected health information
- B. Personal health information
- C. Personal identity information
- D. Personally identifiable information
正解: D
質問 54
What is one popular network protocol that is usually enabled by default on home routers that creates a large attack surface?
- A. Domain Name System Security Extensions (DNSSEC)
- B. Open virtual private network (VPN)
- C. Universal Plug and Play (UPnP)
- D. Network Address Translation (NAT)
正解: C
質問 55
An IoT security architect needs to secure data in motion. Which of the following is a common vulnerability used to exploit unsecure data in motion?
- A. Misconfigured Secure Sockets Layer (SSL)/Transport Layer Security (TLS)
- B. Databases and datastores
- C. Lack of memory space isolation
- D. External flash access
正解: A
質問 56
Which of the following attacks is a reflected Distributed Denial of Service (DDoS) attack?
- A. Smurf
- B. Teardrop
- C. SYN flood
- D. Ping of Death
正解: C
質問 57
An IoT security administrator realizes that when he attempts to visit the administrative website for his devices, he is sent to a fake website. To which of the following attacks has he likely fallen victim?
- A. Birthday attack
- B. Denial of Service (DoS)
- C. Buffer overflow
- D. Domain name system (DNS) poisoning
正解: D
質問 58
Which of the following encryption standards should an IoT developer select in order to implement an asymmetric key pair?
- A. Advanced Encryption Standard (AES)
- B. Temporal Key Integrity Protocol (TKIP)
- C. Triple Data Encryption Standard (3DES)
- D. Elliptic curve cryptography (ECC)
正解: D
質問 59
A manufacturer wants to ensure that approved software is delivered securely and can be verified prior to installation on its IoT devices. Which of the following technologies allows the manufacturer to meet this requirement?
- A. Advanced Encryption Standard (AES)
- B. Public Key Infrastructure (PKI)
- C. Internet Protocol Security (IPsec)
- D. Generic Routing Encapsulation (GRE)
正解: B
質問 60
You work for an IoT software-as-a-service (SaaS) provider. Your boss has asked you to research a way to effectively dispose of stored sensitive customer dat a. Which of the following methods should you recommend to your boss?
- A. Overwriting
- B. Degaussing
- C. Physical destruction
- D. Crypto-shredding
正解: C
質問 61
......
試験問題解答ブレーン問題集でITS-110試験問題集PDF問題:https://www.passtest.jp/CertNexus/ITS-110-shiken.html
ITS-110試験問題集、ITS-110練習テスト問題:https://drive.google.com/open?id=1elyjlLXjgDo7NcKhGeFP09t34GGQrQ-L