nerdexam
CompTIA

PT0-002 · Question #138

Which of the following is the MOST common vulnerability associated with IoT devices that are directly connected to the Internet?

The correct answer is D. The existence of default passwords. The IoT provides a unique opportunity for manufacturers to build devices with the ability to communicate and perform specialized functions. However, because of the lack of rigorous testing, many devices have several insecure defaults that come preconfigured, such as the…

Vulnerability discovery and analysis

Question

Which of the following is the MOST common vulnerability associated with IoT devices that are directly connected to the Internet?

Options

  • AUnsupported operating systems
  • BSusceptibility to DDoS attacks
  • CInability to network
  • DThe existence of default passwords

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    6% (2)
  • D
    91% (30)

Explanation

The IoT provides a unique opportunity for manufacturers to build devices with the ability to communicate and perform specialized functions. However, because of the lack of rigorous testing, many devices have several insecure defaults that come preconfigured, such as the username and password. In many cases, the manufacturer has hard-coded these credentials and made them very difficult or impossible to remove. This can be dangerous, as once a malicious actor knows the type of device that is in use, they can then research the default username and password online. As a result, the team should research the default credentials for each IoT product you target during the PenTest.

Topics

#IoT security#common vulnerabilities#default credentials#device security

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice