nerdexam
Isaca

CISA · Question #554

Which of the following is the BEST way to ensure Internet of Things (IoT) devices do not retain default admin passwords?

The correct answer is A. Performing configuration management throughout the asset life cycle. Configuration management throughout the asset life cycle is the best approach because it ensures IoT devices are properly configured-including changing default admin credentials-at provisioning and maintained securely throughout their operational life. Default password changes…

Submitted by carter_n· Apr 18, 2026Protection of Information Assets

Question

Which of the following is the BEST way to ensure Internet of Things (IoT) devices do not retain default admin passwords?

Options

  • APerforming configuration management throughout the asset life cycle
  • BConducting file-sharing reviews throughout the asset life cycle
  • CImplementing vulnerability management throughout the asset life cycle
  • DAuditing activity logs throughout the asset life cycle

How the community answered

(53 responses)
  • A
    70% (37)
  • B
    17% (9)
  • C
    4% (2)
  • D
    9% (5)

Explanation

Configuration management throughout the asset life cycle is the best approach because it ensures IoT devices are properly configured-including changing default admin credentials-at provisioning and maintained securely throughout their operational life. Default password changes are a configuration activity, not a vulnerability or file-sharing issue. Option B (file-sharing reviews) is irrelevant to password management. Option C (vulnerability management) identifies security weaknesses but does not directly enforce configuration changes like password resets. Option D (auditing activity logs) is detective and would only reveal misuse after default credentials were exploited.

Topics

#IoT Security#Configuration Management#Password Security#Security Controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice