nerdexam
EC-Council

212-82 · Question #110

You recently purchased a smart thermostat for your home. It allows you to control the temperature remotely through a mobile app. Considering the security of your new smart thermostat, which of the…

The correct answer is B. Leaving the thermostat connected to the "Guest" Wi-Fi network in your home, which is open to all. Connecting a smart thermostat to an unsecured guest Wi-Fi network is the least effective security measure, as it exposes the device to potential unauthorized access and monitoring.

Submitted by haru.x· Mar 6, 2026Cloud Security Architecture

Question

You recently purchased a smart thermostat for your home. It allows you to control the temperature remotely through a mobile app. Considering the security of your new smart thermostat, which of the following actions would be the LEAST effective In protecting It from unauthorized access?

Options

  • AKeeping the thermostat firmware updated with the latest security patches from the manufacturer.
  • BLeaving the thermostat connected to the "Guest" Wi-Fi network in your home, which is open to all
  • CChanging the default password for the mobile app and thermostat upon initial setup.
  • DEnabling remote access to the thermostat only on your secure home Wi-Fi network.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    75% (24)
  • C
    16% (5)
  • D
    6% (2)

Why each option

Connecting a smart thermostat to an unsecured guest Wi-Fi network is the least effective security measure, as it exposes the device to potential unauthorized access and monitoring.

AKeeping the thermostat firmware updated with the latest security patches from the manufacturer.

Keeping the firmware updated is highly effective as it applies security patches, closing known vulnerabilities that could be exploited for unauthorized access.

BLeaving the thermostat connected to the "Guest" Wi-Fi network in your home, which is open to allCorrect

Leaving the thermostat connected to an 'open to all' Guest Wi-Fi network is the LEAST effective action because guest networks often lack encryption and isolation from other devices, making the smart thermostat and its traffic highly vulnerable to interception and unauthorized access by anyone on that network.

CChanging the default password for the mobile app and thermostat upon initial setup.

Changing default passwords is a fundamental and highly effective security practice, preventing unauthorized access by attackers who commonly try default credentials.

DEnabling remote access to the thermostat only on your secure home Wi-Fi network.

Enabling remote access only on a secure home Wi-Fi network ensures that external access attempts are filtered through your secure router and network, adding a significant layer of protection.

Concept tested: IoT device security best practices

Source: https://www.cisa.gov/resources-tools/resources/internet-things-iot-security-best-practices

Topics

#IoT security#network segmentation#firmware updates#default passwords

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice