
PassTest ITS-110問題集102問でCertified IoT Security Practitionerを確実実践
リアル最新ITS-110試験問題ITS-110問題集
IoTは急速に成長しており、2025年までにIoTデバイスの数が750億に達すると予想されています。増加するデバイス数は、サイバー攻撃から自社のIoTインフラストラクチャを保護するスキルを持つ専門家が必要であるという重要なセキュリティ上の課題を提起しています。ITS-110認定は、プロフェッショナルが自社のIoTネットワークとデバイスを保護するために必要なスキルと知識を習得するのを支援します。
質問 # 28
A manufacturer wants to ensure that approved software is delivered securely and can be verified prior to installation on its IoT devices. Which of the following technologies allows the manufacturer to meet this requirement?
- A. Public Key Infrastructure (PKI)
- B. Generic Routing Encapsulation (GRE)
- C. Internet Protocol Security (IPsec)
- D. Advanced Encryption Standard (AES)
正解:A
質問 # 29
An embedded engineer wants to implement security features to be sure that the IoT gateway under development will only load verified images. Which of the following countermeasures could be used to achieve this goal?
- A. Harden the update server
- B. Enforce a secure boot function
- C. Implement Over-The-Air (OTA) updates
- D. Enforce a measured boot function
正解:B
質問 # 30
An embedded developer is about to release an IoT gateway. Which of the following precautions must be taken to minimize attacks due to physical access?
- A. Allow access only to the software
- B. Remove all unneeded physical ports
- C. Allow easy access to components
- D. Install a firewall on network ports
正解:B
質問 # 31
If an attacker were able to gain access to a user's machine on your network, which of the following actions would she most likely take next?
- A. Escalate privileges
- B. Initiate reconnaissance
- C. Perform port scanning
- D. Start log scrubbing
正解:C
質問 # 32
A DevOps engineer wants to provide secure network services to an IoT/cloud solution. Which of the following countermeasures should be implemented to mitigate network attacks that can render a network useless?
- A. Web application firewall (WAF)
- B. Deep Packet Inspection (DPI)
- C. Denial of Service (DoS)/Distributed Denial of Service (DDoS) mitigation
- D. Network firewall
正解:C
質問 # 33
During a brute force test on his users' passwords, the security administrator found several passwords that were cracked quickly. Which of the following passwords would have taken the longest to crack?
- A. 123my456password789
- B. **myPASSword**
- C. GUESSmyPASSWORD
- D. Gu3$$MyP@s$w0Rd
正解:D
質問 # 34
An IoT security administrator is concerned that someone could physically connect to his network and scan for vulnerable devices. Which of the following solutions should he install to prevent this kind of attack?
- A. Host Intrusion Detection System (HIDS)
- B. Network Intrusion Detection System (NIDS)
- C. Media Access Control (MAC)
- D. Network Access Control (NAC)
正解:B
質問 # 35
An IoT manufacturer needs to ensure that firmware flaws can be addressed even after their devices have been deployed. Which of the following methods should the manufacturer use to meet this requirement?
- A. Ensure that device can accept Over-the-Air (OTA) firmware updates
- B. Ensure that the bootloader can be accessed remotely using Secure Shell (SSH)
- C. Ensure that ail firmware is signed using digital certificates prior to deployment
- D. Ensure that a writable copy of the device's configuration is stored in flash memory
正解:A
質問 # 36
Which of the following attacks relies on the trust that a website has for a user's browser?
- A. Phishing
- B. SQL Injection (SQLi)
- C. Cross-Site Scripting (XSS)
- D. Cross-Site Request Forgery (CSRF)
正解:D
質問 # 37
A user grants an IoT manufacturer consent to store personally identifiable information (PII). According to the General Data Protection Regulation (GDPR), when is an organization required to delete this data?
- A. Within sixty days after collection, unless encrypted
- B. Within ninety days after collection, unless required for a legal proceeding
- C. Within seven days of being transferred to secure, long-term storage
- D. Within thirty days of a user's written request
正解:D
質問 # 38
An IoT security architect needs to secure data in motion. Which of the following is a common vulnerability used to exploit unsecure data in motion?
- A. Misconfigured Secure Sockets Layer (SSL)/Transport Layer Security (TLS)
- B. External flash access
- C. Lack of memory space isolation
- D. Databases and datastores
正解:A
質問 # 39
A site administrator is not enforcing strong passwords or password complexity. To which of the following types of attacks is this system probably MOST vulnerable?
- A. Collision attack
- B. Dictionary attack
- C. Key logger attack
- D. Phishing attack
正解:B
質問 # 40
A hacker is able to extract users' names, birth dates, height, and weight from an IoT manufacturer's user portal. Which of the following types of data has been compromised?
- A. Personally identifiable information
- B. Personal identity information
- C. Protected health information
- D. Personal health information
正解:A
質問 # 41
Which of the following attacks utilizes Media Access Control (MAC) address spoofing?
- A. Network device fuzzing
- B. Network Address Translation (NAT)
- C. Unsecured network ports
- D. Man-in-the-middle (MITM)
正解:D
質問 # 42
The network administrator for an organization has read several recent articles stating that replay attacks are on the rise. Which of the following secure protocols could the administrator implement to prevent replay attacks via remote workers' VPNs? (Choose three.)
- A. Password Authentication Protocol (PAP)
- B. Simple Network Management Protocol (SNMP)
- C. Challenge Handshake Authentication Protocol (CHAP)
- D. Internet Protocol Security (IPSec)
- E. Layer 2 Tunneling Protocol (L2TP)
- F. Interior Gateway Routing Protocol (IGRP)
- G. Enhanced Interior Gateway Routing Protocol (EIGRP)
正解:C、D、E
質問 # 43
An IoT security administrator wishes to mitigate the risk of falling victim to Distributed Denial of Service (DDoS) attacks. Which of the following mitigation strategies should the security administrator implement? (Choose two.)
- A. Require the use of X.509 digital certificates for all incoming requests
- B. Block all inbound packets with an internal source IP address
- C. Enable unused Transmission Control Protocol (TCP) service ports in order to create a honeypot
- D. Block the use of Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) through his perimeter firewall
- E. Block all inbound packets originating from service ports
正解:A、D
質問 # 44
Which of the following attacks would most likely be used to discover users, printers, and other objects within a network?
- A. LDAP Injection
- B. SYN flood
- C. Distributed Denial of Service (DDoS)
- D. Denial of Service (DoS)
正解:A
質問 # 45
An IoT security architect needs to minimize the security risk of a radio frequency (RF) mesh application. Which of the following might the architect consider as part of the design?
- A. Allow implicit trust of all gateways since they are the link to the internet.
- B. Make pairing between nodes very easy so that troubleshooting is reduced.
- C. Encrypt data transmission between nodes at the physical/logical layers.
- D. Prevent nodes from being rejected to keep the value of the network as high as possible.
正解:C
質問 # 46
Passwords should be stored...
- A. For no more than 30 days.
- B. As a hash value.
- C. Inside a digital certificate.
- D. Only in cleartext.
正解:B
質問 # 47
A corporation's IoT security administrator has configured his IoT endpoints to send their data directly to a database using Secure Sockets Layer (SSL)/Transport Layer Security (TLS). Which entity provides the symmetric key used to secure the data in transit?
- A. The database server
- B. The administrator's machine
- C. The Key Distribution Center (KDC)
- D. The IoT endpoint
正解:A
質問 # 48
You work for a business-to-consumer (B2C) IoT device company. Your organization wishes to publish an annual report showing statistics related to the volume and variety of sensor data it collects. Which of the following should your organization do prior to using this information?
- A. Require customers to sign a subscription license
- B. Confirm the devices they've sold are turned on
- C. Ensure all sensors are running the latest software
- D. Remove any customer-specific data
正解:D
質問 # 49
......
ITS-110別格な問題集で最上級の成績にさせるITS-110問題:https://www.passtest.jp/CertNexus/ITS-110-shiken.html
手に入れよう!最新ITS-110認定の有効な試験問題集解答:https://drive.google.com/open?id=1d89riAuKFLAwbjFRa_3Z1wGRYsimXshf