nerdexam
CompTIA

PT0-001 · Question #29

Consumer-based IoT devices are often less secure than systems built for traditional desktop computers. Which of the following BEST describes the reasoning for this?

The correct answer is A. Manufacturers developing IoT devices are less concerned with security. Consumer IoT devices are typically less secure because manufacturers deprioritize security in favor of lower production costs and faster time-to-market.

Vulnerability discovery and analysis

Question

Consumer-based IoT devices are often less secure than systems built for traditional desktop computers. Which of the following BEST describes the reasoning for this?

Options

  • AManufacturers developing IoT devices are less concerned with security.
  • BIt is difficult for administrators to implement the same security standards across the board.
  • CIoT systems often lack the hardware power required by more secure solutions.
  • DRegulatory authorities often have lower security requirements for IoT systems.

How the community answered

(59 responses)
  • A
    88% (52)
  • B
    5% (3)
  • C
    5% (3)
  • D
    2% (1)

Why each option

Consumer IoT devices are typically less secure because manufacturers deprioritize security in favor of lower production costs and faster time-to-market.

AManufacturers developing IoT devices are less concerned with security.Correct

IoT manufacturers routinely sacrifice security practices - such as unique default credentials, firmware signing, and vulnerability patching pipelines - to cut costs and ship products faster, resulting in devices with fundamental insecurities built in by design. This manufacturer-level disregard for security is the root cause, making devices difficult or impossible to adequately secure even when administrators attempt remediation after deployment.

BIt is difficult for administrators to implement the same security standards across the board.

Administrator difficulty in applying uniform security standards is an operational challenge that follows from insecure devices already being deployed, not the underlying reason devices are designed without adequate security.

CIoT systems often lack the hardware power required by more secure solutions.

While some IoT devices have constrained hardware, many have sufficient processing capability to support basic security controls but still ship insecure because manufacturers choose not to implement them as a cost-saving measure.

DRegulatory authorities often have lower security requirements for IoT systems.

Regulatory requirements do not directly cause IoT insecurity - many jurisdictions do mandate minimum security standards, and their laxity is a secondary factor compared to manufacturer economic priorities.

Concept tested: IoT security weaknesses and manufacturer security priorities

Source: https://www.nist.gov/programs-projects/nist-cybersecurity-iot-program

Topics

#IoT security#hardware constraints#security by design#embedded systems

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice