ITS-110 Sample Questions & Answers
Expect the heaviest weighting on locking down IoT interfaces, then authentication, authorization and accounting controls, protecting data and network services, software and firmware hardening, privacy and compliance requirements, and the physical security of devices.
Launch the full ITS-110 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Enhancing Physical Security · Hardware Interface Security
An organization is deploying IoT sensors in a public-facing, physically accessible area. The security team is concerned about attackers connecting a device to the sensor's debug port (e.g., JTAG or UART) to extract firmware or cryptographic keys. Which of the following is the MOST effective countermeasure against this specific threat?
Show answer & explanation
Correct answer: B
The most direct and effective countermeasure against attacks via debug ports is to disable them completely in the final production version of the firmware. This is often done by blowing an eFuse on the microcontroller, making the change irreversible. While encryption is important, an attacker with debug access could potentially bypass it. Tamper-evident seals detect attacks but don't prevent them, and network access control is irrelevant to this physical attack vector.
- Question 2Intermediate
Implementing Authentication, Authorization, and Accounting · MQTT Authorization
A cloud-based IoT platform uses an MQTT broker to communicate with thousands of devices. To ensure that a compromised device can only publish data to its own designated topic (e.g.,
devices/123/data) and subscribe only to its command topic (e.g.,devices/123/commands), which security mechanism should be configured on the MQTT broker?Show answer & explanation
Correct answer: C
While TLS certificates and username/password handle authentication (who the device is), they do not control authorization (what the device is allowed to do). Topic-based Access Control Lists (ACLs) are the specific mechanism used in MQTT brokers to enforce rules about which clients can publish or subscribe to specific topic patterns. This directly addresses the principle of least privilege required by the scenario.
- Question 3Beginner
Addressing Privacy Concerns · Data Minimization
A company that manufactures smart home cameras is facing criticism over privacy. To demonstrate a commitment to the principle of data minimization, which action would be most effective?
Show answer & explanation
Correct answer: B
Data minimization is the principle of collecting and retaining only the data that is strictly necessary for a specific purpose. An 'event-only' recording mode directly applies this principle by avoiding the collection of continuous, unnecessary footage and only capturing data relevant to a security event (motion). The other options either increase data collection or relate to security and transparency, not minimization.
- Question 4Beginner
Securing IoT Portals · Web Application Attacks
A security analyst is reviewing logs from a web application firewall (WAF) that protects an IoT device management portal. The analyst observes a series of HTTP requests targeting a user profile page with the following parameter:
?user_id=123' OR '1'='1'. This pattern is indicative of which type of attack?Show answer & explanation
Correct answer: B
The payload
' OR '1'='1'is a classic SQL injection technique. The attacker is attempting to manipulate the backend SQL query by appending a condition that always evaluates to true, potentially bypassing authentication or retrieving all records from a database table. XSS involves injecting client-side scripts, CSRF tricks a user into performing an unwanted action, and path traversal involves accessing files outside the intended directory. - Question 5AdvancedSelect 3
Enhancing Physical Security · Side-Channel Attack Countermeasures
To prevent a power analysis side-channel attack, where an attacker measures fluctuations in a device's power consumption to deduce cryptographic operations, a hardware engineer could implement which of the following countermeasures? (Select THREE)
Show answer & explanation
Correct answers: A, B, D
Adding random noise makes it much harder for an attacker to isolate the small power fluctuations related to cryptographic operations.
Constant-time algorithms ensure that operations take the same amount of time and similar power regardless of the data being processed, removing data-dependent variations an attacker could exploit.
Blinding involves randomizing the input to a cryptographic function so that the power consumption patterns are decorrelated from the actual secret key or data.
- Question 6Intermediate
Securing Software/Firmware · Firmware Rollback Protection
A developer is building firmware for a battery-powered IoT device. The firmware needs to be updated securely, but the update process must not allow an attacker to downgrade the device to an older, vulnerable firmware version. What is the name of the mechanism that prevents this type of attack?
Show answer & explanation
Correct answer: C
Anti-rollback protection is a specific security feature that prevents a device from accepting and installing a firmware version that is older than the one currently installed. This is typically implemented by storing the current version number in a secure, one-way modifiable location (like an eFuse or trusted storage) and rejecting any update with a lower version number. Secure boot and code signing are related but do not inherently prevent downgrades.
- Question 7Beginner
Addressing Privacy Concerns · Data Subject Rights
A new IoT regulation requires that users are able to request and receive a copy of all personal data collected by their smart devices. Fulfilling this requirement is a key component of which privacy principle?
Show answer & explanation
Correct answer: B
The 'Right to Access' (also known as the 'Right of Access' or linked to 'Data Portability' in regulations like GDPR) is the specific right of individuals (data subjects) to obtain a copy of their personal data that is being processed by an organization. This allows users to understand what data is held about them and to verify its lawfulness.
- Question 8Beginner
Securing Network Services · Network Segmentation
A system administrator needs to segment an IoT network to isolate a group of sensitive industrial sensors from the rest of the corporate network and other less-sensitive IoT devices. All devices are connected to the same physical switches. Which technology provides the most common and effective way to achieve this logical separation on the existing hardware?
Show answer & explanation
Correct answer: B
VLANs (Virtual Local Area Networks) allow a network administrator to logically segment a single physical network into multiple, isolated broadcast domains. This is the standard method for separating traffic (like industrial sensors vs. corporate data) on the same physical switch infrastructure. Air gapping requires separate physical hardware, a VPN is for remote access, and a DMZ is typically for external-facing services.
- Question 9Intermediate
Implementing Authentication, Authorization, and Accounting · Delegated Authorization Frameworks
An IoT solutions provider wants to implement a centralized authentication and authorization system for its devices and users. They need a solution that supports third-party identity providers (like Google or Facebook) and can issue access tokens for API calls between microservices in their cloud backend. Which framework is the industry standard for this scenario?
Show answer & explanation
Correct answer: D
OAuth 2.0 is the industry-standard protocol for authorization, allowing applications to obtain limited access to user accounts on an HTTP service. OpenID Connect (OIDC) is a simple identity layer built on top of OAuth 2.0 that provides authentication. This combination is perfectly suited for modern web/cloud applications, supporting third-party identity providers and token-based API security. RADIUS, LDAP, and Kerberos are older protocols not typically used for this type of web-centric, federated identity scenario.
- Question 10Intermediate
Securing IoT Portals · Threat Modeling with STRIDE
A security team is conducting a threat modeling exercise for a new smart lock product. They are using the STRIDE methodology. The threat of an attacker spoofing the identity of the legitimate user's smartphone to unlock the door would be categorized under which STRIDE element?
Show answer & explanation
Correct answer: A
STRIDE is a mnemonic for six threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. The act of pretending to be another entity (in this case, the user's smartphone) falls directly under the 'Spoofing' category.
Ready for the real thing?
The full ITS-110 simulator has every exam-style question, timed mode, and instant scoring.