ITS-110 Certified Internet of Things Security Practitioner Practice Questions
Prepare for ITS-110 with more than an answer.
- Exam fee
- $250 USD
- Level
- Practitioner
- Valid for
- 3 years
Domains covered on the exam 7
- Securing IoT Portals29%
- Implementing Authentication, Authorization, and Accounting14%
- Securing Network Services14%
- Securing Data14%
- Addressing Privacy Concerns12%
- Securing Software/Firmware10%
- Enhancing Physical Security7%
- 1
Case Study:
A large-scale logistics company, 'Global-Ship', is upgrading its fleet of delivery vehicles with IoT gateways. These gateways collect telematics data (GPS, speed, fuel level) and data from wireless sensors on packages (temperature, humidity). The data is aggregated at the gateway and sent to a central cloud platform for real-time tracking and analysis. The company has several critical security and operational requirements.
Current Situation: The initial prototype uses unencrypted MQTT over a cellular connection. Device identity is based on a static, hardcoded username and password in the gateway's configuration file. The gateways run a standard Linux distribution, but no process is in place for remote software updates. Physical access to the vehicles is possible when parked at distribution centers.
Requirements:
- Data Confidentiality and Integrity: All data sent from the gateway to the cloud must be protected from eavesdropping and modification.
- Unique Device Identity: Each gateway must have a unique, non-repudiable, and difficult-to-clone identity.
- Secure Updates: A mechanism must exist to securely deploy patches and new features to the gateways remotely.
- Physical Security: The gateway's identity and firmware must be protected even if an attacker gains physical access.
Which of the following proposals BEST addresses all the stated requirements?
graph TD subgraph Vehicle PKG_Sensor_A[Package Sensor] -->|BLE| Gateway PKG_Sensor_B[Package Sensor] -->|BLE| Gateway GPS[GPS Module] -->|Serial| Gateway end subgraph CloudPlatform MQTT_Broker[MQTT Broker] Data_Analytics[Analytics Service] Device_Mgmt[Device Management] end Gateway -->(Cellular Network) --> MQTT_Broker MQTT_Broker --> Data_Analytics Device_Mgmt --> GatewayShow answer details
Correct answer: D
This option is the most comprehensive. MQTTS with mTLS addresses data protection and provides a strong, unique identity. Storing the certificate's private key in a TPM protects it from physical extraction (Requirement 4). A signed OTA update process ensures secure updates (Requirement 3). Secure Boot leverages the TPM to ensure firmware integrity at boot time, further enhancing physical security. This solution effectively covers all four requirements with industry best practices.
- 2
The Zigbee protocol specification includes a security model that relies on a central entity to manage network keys and admit devices to the network. What is this central entity called?
Show answer details
Correct answer: C
In a centralized Zigbee security model, the Trust Center is the dedicated device responsible for configuring and distributing security keys (like the Network Key) and managing device admissions. The role of the Trust Center is typically performed by the Zigbee Coordinator.
- 3
A security auditor is examining the API for an IoT cloud platform and discovers that API keys do not have an expiration date. This violates which security best practice?
Show answer details
Correct answer: C
Security best practices dictate that all credentials, including API keys and access tokens, should have a limited lifetime and be rotated regularly. This minimizes the window of opportunity for an attacker to use a compromised key. Keys without an expiration date pose a significant long-term risk.
- 4
When using asymmetric cryptography to digitally sign a firmware update, the manufacturer uses their ________ to create the signature, and the IoT device uses the manufacturer's ________ to verify the signature.
Show answer details
Correct answer: B
In a digital signature scheme, the sender (manufacturer) signs the data using their secret private key. The receiver (IoT device) then uses the sender's corresponding public key, which can be widely distributed, to verify that the signature is valid and that the data has not been tampered with.
- 5
A hospital is deploying a network of IoT infusion pumps. To prevent these critical devices from being targeted by malware spreading from the hospital's guest Wi-Fi network, which network security design principle is most important to apply?
Show answer details
Correct answer: A
Network segmentation is the practice of dividing a network into smaller, isolated segments. In this scenario, the infusion pumps should be placed on a dedicated, isolated VLAN or network segment that is firewalled off from both the guest network and the main corporate network. This prevents lateral movement of threats and contains potential breaches. While the other options are good security practices, segmentation provides the direct protection required by the scenario.
graph TD subgraph Unsegmented Network [X - POOR DESIGN] Internet -- Firewal_A[Firewall] --- Switch_A[Switch] Switch_A --- Guest_WiFi_A[Guest WiFi] Switch_A --- Infusion_Pump_A[Infusion Pump] Switch_A --- Doctor_PC_A[Doctor PC] end subgraph Segmented Network [✔ - GOOD DESIGN] Internet -- Firewall_B[Firewall] --- Core_Switch[Core Switch] Core_Switch -- VLAN 10 --> Guest_WiFi_B[Guest WiFi] Core_Switch -- VLAN 20 --> Infusion_Pump_B[Infusion Pump] Core_Switch -- VLAN 30 --> Doctor_PC_B[Doctor PC] Firewall_B -- ACLs --> Core_Switch end - 6
A smart utility company is deploying a large-scale mesh network of smart meters using 6LoWPAN. To prevent unauthorized devices from joining the network and injecting malicious data, which of the following is the most effective and resource-efficient security mechanism to implement at the network layer for device onboarding?
Show answer details
Correct answer: C
Protocol for Carrying Authentication for Network Access (PANA) is a network-layer protocol specifically designed for network access authentication in IP-based networks, making it suitable for 6LoWPAN. It works with the Extensible Authentication Protocol (EAP) to provide robust authentication before a device is granted full network access. IPsec is too heavyweight for many constrained 6LoWPAN devices. MAC filtering is easily spoofed and not scalable. DTLS operates at the transport layer, not the network layer for initial access control.
- 7
A medical device manufacturer is designing an implantable glucose monitor that transmits data to a patient's smartphone via Bluetooth Low Energy (BLE). To comply with HIPAA and protect sensitive health information, which BLE Security Mode should be mandated for the connection?
Show answer details
Correct answer: C
For handling sensitive Protected Health Information (PHI) under HIPAA, the highest level of security is required. BLE Security Mode 1, Level 4 mandates the use of LE Secure Connections, which uses Elliptic Curve Diffie-Hellman (ECDH) key exchange for strong encryption and protects against passive eavesdropping and man-in-the-middle attacks. The lower security levels (1, 2, and 3) are not sufficient for protecting sensitive medical data.
- 8
During a security audit of an industrial IoT deployment, a penetration tester discovers that firmware updates for programmable logic controllers (PLCs) are being delivered over-the-air (OTA) without any verification of the update source's identity. To mitigate the risk of malicious firmware injection, which TWO of the following controls are most critical to implement? (Select TWO)
Show answer details
Correct answer: B, C
Digital signatures provide authenticity (proving the firmware came from the manufacturer) and integrity (ensuring it wasn't altered).
Secure boot ensures that the PLC will only load and execute firmware that has been cryptographically verified (e.g., by checking the digital signature), thus preventing unauthorized code from running.
- 9
A security architect is designing a system for a remote environmental monitoring station powered by a solar panel and battery. The station uses a low-power wide-area network (LPWAN) to send small data packets infrequently. To protect the data packets from eavesdropping and tampering with minimal energy consumption, which protocol is most suitable?
Show answer details
Correct answer: D
Constrained Application Protocol (CoAP) is designed for constrained devices and networks, running over UDP. Datagram Transport Layer Security (DTLS) provides security equivalent to TLS but is adapted for datagram-based protocols like UDP, making it ideal for low-power, lossy networks. This combination is energy-efficient and provides strong security. TLS over TCP, IPsec, and SSH are all too resource-intensive for this use case.
- 10
True or False: In an IoT context, implementing Privacy by Design means that privacy considerations are addressed as a secondary feature after the main functionality has been developed and tested.
Show answer details
Correct answer: B
The statement is false. Privacy by Design is a core principle that dictates privacy should be embedded into the design and architecture of IT systems and business practices from the very beginning of the development lifecycle, not added as an afterthought. It emphasizes proactive rather than reactive measures.
