A DevOps engineer wants to provide secure network services to an IoT/cloud solution. Which of the following countermeasures should be implemented to mitigate network attacks that can render a network useless?
A. Web application firewall (WAF)
B. Network firewall
C. Deep Packet Inspection (DPI)
D. Denial of Service (DoS)/Distributed Denial of Service (DDoS) mitigation
正解:D
質問 2:
A hacker is attempting to exploit a known software flaw in an IoT portal in order to modify the site's administrative configuration. Which of the following BEST describes the type of attack the hacker is performing?
A. Privilege escalation
B. Transmission control protocol (TCP) flooding
C. Application fuzzing
D. Birthday attack
正解:A
質問 3:
An IoT gateway will be brokering data on numerous northbound and southbound interfaces. A security practitioner has the data encrypted while stored on the gateway and encrypted while transmitted across the network. Should this person be concerned with privacy while the data is in use?
A. Yes, because the hash wouldn't protect the integrity of the data.
B. No, because the data is inside the CPU's secure region while being used.
C. Yes, because the data is vulnerable during processing.
D. No, since the data is already encrypted while at rest and while in motion.
正解:C
質問 4:
An IoT security administrator realizes that when he attempts to visit the administrative website for his devices, he is sent to a fake website. To which of the following attacks has he likely fallen victim?
A. Domain name system (DNS) poisoning
B. Denial of Service (DoS)
C. Birthday attack
D. Buffer overflow
正解:A
質問 5:
An IoT software developer wants the users of her software tools to know if they have been modified by someone other than her. Which of the following tools or techniques should she use?
A. Encryption
B. Fuzzing
C. Hashing
D. Obfuscation
正解:C
質問 6:
An IoT system administrator discovers that hackers are using rainbow tables to compromise user accounts on their cloud management portal. What should the administrator do in order to mitigate this risk?
A. Implement robust password policies
B. Implement URL filtering
C. Implement granular role-based access
D. Implement certificates on all login pages
正解:C
質問 7:
A hacker is able to access privileged information via an IoT portal by modifying a SQL parameter in a URL. Which of the following BEST describes the vulnerability that allows this type of attack?
A. Insecure HTTP session management
B. Unsecure direct object references
C. Unhandled malformed URLs
D. Unvalidated redirect or forwarding
正解:C
質問 8:
An IoT system administrator discovers that end users are able to access administrative features on the company's IoT management portal. Which of the following actions should the administrator take to address this issue?
A. Implement account lockout policies
B. Implement digitally signed firmware updates
C. Implement granular role-based access
D. Implement password complexity policies
正解:C
1313 お客様のコメント





Matsumoto -
ITS-110のデモ問題集をチェックしてイイっと思ったから購入して、そして本当に内容もすごく素晴らしかった。そして試験にも合格だ。完璧