PT0-002 · Question #138
Which of the following is the MOST common vulnerability associated with IoT devices that are directly connected to the Internet?
The correct answer is D. The existence of default passwords. The IoT provides a unique opportunity for manufacturers to build devices with the ability to communicate and perform specialized functions. However, because of the lack of rigorous testing, many devices have several insecure defaults that come preconfigured, such as the…
Question
Which of the following is the MOST common vulnerability associated with IoT devices that are directly connected to the Internet?
Options
- AUnsupported operating systems
- BSusceptibility to DDoS attacks
- CInability to network
- DThe existence of default passwords
How the community answered
(33 responses)- A3% (1)
- B6% (2)
- D91% (30)
Explanation
The IoT provides a unique opportunity for manufacturers to build devices with the ability to communicate and perform specialized functions. However, because of the lack of rigorous testing, many devices have several insecure defaults that come preconfigured, such as the username and password. In many cases, the manufacturer has hard-coded these credentials and made them very difficult or impossible to remove. This can be dangerous, as once a malicious actor knows the type of device that is in use, they can then research the default username and password online. As a result, the team should research the default credentials for each IoT product you target during the PenTest.
Topics
Community Discussion
No community discussion yet for this question.