nerdexam
Isaca

CISA · Question #170

Which of the following is the BEST recommendation by an IS auditor to prevent unauthorized access to Internet of Things (IoT) devices?

The correct answer is C. IoT devices should require identification and authentication. Requiring identification and authentication ensures that only authorized users or systems can access the IoT devices. This is a fundamental security measure to prevent unauthorized access. Without proper authentication, IoT devices can be easily compromised, posing significant se

Submitted by yaw92· Apr 18, 2026Protection of Information Assets

Question

Which of the following is the BEST recommendation by an IS auditor to prevent unauthorized access to Internet of Things (IoT) devices?

Options

  • AIoT devices should only be accessible from the host network
  • BIoT devices should log and alert on access attempts
  • CIoT devices should require identification and authentication
  • DIoT devices should monitor the use of device system accounts

How the community answered

(47 responses)
  • A
    4% (2)
  • B
    9% (4)
  • C
    68% (32)
  • D
    19% (9)

Explanation

Requiring identification and authentication ensures that only authorized users or systems can access the IoT devices. This is a fundamental security measure to prevent unauthorized access. Without proper authentication, IoT devices can be easily compromised, posing significant security While restricting access to the host network, logging access attempts, and monitoring system accounts are also good practices, they do not directly prevent unauthorized access. Authentication and identification are essential first steps in protecting IoT devices.

Topics

#IoT Security#Access Control#Authentication#Preventive Controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice