
[Dec-2023] ITS-110 Certification with Actual Questions from DumpStillValid
Updated ITS-110 Dumps PDF - ITS-110 Real Valid Brain Dumps With 102 Questions!
NEW QUESTION # 36
An IoT gateway will be brokering data on numerous northbound and southbound interfaces. A security practitioner has the data encrypted while stored on the gateway and encrypted while transmitted across the network. Should this person be concerned with privacy while the data is in use?
- A. Yes, because the hash wouldn't protect the integrity of the data.
- B. Yes, because the data is vulnerable during processing.
- C. No, because the data is inside the CPU's secure region while being used.
- D. No, since the data is already encrypted while at rest and while in motion.
Answer: B
NEW QUESTION # 37
A web application is connected to an IoT endpoint. A hacker wants to steal data from the connection between them. Which of the following is NOT a method of attack that could be used to facilitate stealing data?
- A. Cross-Site Scripting (XSS)
- B. LDAP Injection
- C. SQL Injection (SQLi)
- D. Cross-Site Request Forgery (CSRF)
Answer: B
NEW QUESTION # 38
An IoT system administrator wants to mitigate the risk of rainbow table attacks. Which of the following methods or technologies can the administrator implement in order to address this concern?
- A. Require frequent password changes
- B. Enable account database encryption
- C. Enable account lockout
- D. Require complex passwords
Answer: B
NEW QUESTION # 39
An IoT developer wants to ensure that data collected from a remotely deployed power station monitoring system is transferred securely to the cloud. Which of the following technologies should the developer consider?
- A. Blowfish
- B. Transport Layer Security (TLS)
- C. Secure/Multipurpose Internet Mail Extensions (S/MIME)
- D. Message-digest 5 (MD5)
Answer: B
NEW QUESTION # 40
In designing the campus of an IoT device manufacturer, a security consultant was hired to recommend best practices for deterring criminal behavior. Which of the following approaches would he have used to meet his client's needs?
- A. British Standard 7799 part 3 (BS 7799-3)
- B. International Organization for Standardization 17799 (ISO 17799)
- C. Crime Prevention Through Environmental Design (CPTED)
- D. National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)
Answer: C
NEW QUESTION # 41
An IoT security administrator wishes to mitigate the risk of falling victim to Distributed Denial of Service (DDoS) attacks. Which of the following mitigation strategies should the security administrator implement? (Choose two.)
- A. Block all inbound packets originating from service ports
- B. Block all inbound packets with an internal source IP address
- C. Enable unused Transmission Control Protocol (TCP) service ports in order to create a honeypot
- D. Require the use of X.509 digital certificates for all incoming requests
- E. Block the use of Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) through his perimeter firewall
Answer: D,E
NEW QUESTION # 42
Which of the following techniques protects the confidentiality of the information stored in databases?
- A. Encryption
- B. Monitoring
- C. Archiving
- D. Hashing
Answer: A
NEW QUESTION # 43
An IoT security administrator is concerned about an external attacker using the internal device management local area network (LAN) to compromise his IoT devices. Which of the following countermeasures should the security administrator implement? (Choose three.)
- A. Require the use of Password Authentication Protocol (PAP)
- B. Ensure that all administrators access the management server at specific times
- C. Ensure that the Time To Live (TTL) flag for outgoing packets is set to 1
- D. Only allow outbound traffic from the management LAN
- E. Create a separate management virtual LAN (VLAN)
- F. Ensure that all IoT management servers are running antivirus software
- G. Implement 802.1X for authentication
Answer: B,E,G
NEW QUESTION # 44
Passwords should be stored...
- A. For no more than 30 days.
- B. As a hash value.
- C. Only in cleartext.
- D. Inside a digital certificate.
Answer: B
NEW QUESTION # 45
An IoT security administrator realizes that when he attempts to visit the administrative website for his devices, he is sent to a fake website. To which of the following attacks has he likely fallen victim?
- A. Buffer overflow
- B. Birthday attack
- C. Denial of Service (DoS)
- D. Domain name system (DNS) poisoning
Answer: D
NEW QUESTION # 46
An IoT security administrator is concerned that someone could physically connect to his network and scan for vulnerable devices. Which of the following solutions should he install to prevent this kind of attack?
- A. Network Intrusion Detection System (NIDS)
- B. Media Access Control (MAC)
- C. Host Intrusion Detection System (HIDS)
- D. Network Access Control (NAC)
Answer: A
NEW QUESTION # 47
An IoT developer wants to ensure all sensor to portal communications are as secure as possible and do not require any client-side configuration. Which of the following is the developer most likely to use?
- A. IP Security (IPSec)
- B. Secure/Multipurpose Internet Mail Extensions (S/MIME)
- C. Virtual Private Networking (VPN)
- D. Public Key Infrastructure (PKI)
Answer: A
NEW QUESTION # 48
If an attacker were able to gain access to a user's machine on your network, which of the following actions would she most likely take next?
- A. Perform port scanning
- B. Start log scrubbing
- C. Escalate privileges
- D. Initiate reconnaissance
Answer: A
NEW QUESTION # 49
What is one popular network protocol that is usually enabled by default on home routers that creates a large attack surface?
- A. Domain Name System Security Extensions (DNSSEC)
- B. Open virtual private network (VPN)
- C. Network Address Translation (NAT)
- D. Universal Plug and Play (UPnP)
Answer: D
NEW QUESTION # 50
It is a new employee's first day on the job. When trying to access secured systems, he incorrectly enters his credentials multiple times. Which resulting action should take place?
- A. He notifies Human Resources.
- B. He receives a new password.
- C. His account is deleted.
- D. His account is locked.
Answer: D
NEW QUESTION # 51
......
Pass Your ITS-110 Exam Easily With 100% Exam Passing Guarantee: https://www.dumpstillvalid.com/ITS-110-prep4sure-review.html
