exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 620 discussion

Actual exam question from CompTIA's SY0-501
Question #: 620
Topic #: 1
[All SY0-501 Questions]

When considering IoT systems, which of the following represents the GREATEST ongoing risk after a vulnerability has been discovered?

  • A. Difficult-to-update firmware
  • B. Tight integration to existing systems
  • C. IP address exhaustion
  • D. Not using industry standards
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Disguy
Highly Voted 5 years, 3 months ago
This question was on the test. Jan 24, 2020. As GMO has mentioned, updates and patches for these systems are not regularly provided, so I also agree with option A and picked option A at the test as well.
upvoted 43 times
...
GMO
Highly Voted 5 years, 4 months ago
ANS is A Difficulty in patching and update management No matter how much work a manufacturer puts into creating secure hardware and software for its IoT-ready product, new vulnerabilities will inevitably be discovered at some point in the future. Updates are therefore needed to keep IoT devices secure and should be applied as soon as they are released. Yet, the nature and use of IoT devices don’t always make them easy to update regularly — if at all. Think about sensors spread across hundreds of acres of farmland. Or IoT devices on a factory floor that cannot be taken offline for updates without hugely impacting production. Worse still, even where patches can be applied regularly, there’s often no means for the user to rollback changes to the last known good state in the event that an update leads to software corruption or instability.
upvoted 28 times
who__cares123456789___
4 years, 4 months ago
SO, this link https://rickscloud.com/the-risks-of-iot/ seems to list complexity as 1. a main concern-- followed by 2.talk of patching and firmware updates, this article, and the fact that Melvin leads you to patching is enough evidence for me to pick tight intergration!
upvoted 4 times
...
...
zoeyaj
Most Recent 3 years, 4 months ago
Selected Answer: B
after a vulnerability has been discovered
upvoted 1 times
...
Eluis007
3 years, 5 months ago
Difficult-to-update firmware is really a risk related to IoT devices. CompTIA : Some automation products often use vendor-specific software and networking protocols. As with embedded devices, security features can be poorly documented, and patch management/security response processes of vendors can be inadequate. But this is not the greatest risk. The GREATEST risk, in my opinion, is their integration with more critical systems. IoT devices need to measure all kinds of things, including temperature, light levels, humidity, pressure, proximity, motion, gas/chemicals/smoke, heart/breathing rates, and so on. These are implemented as thermocouples/thermistors, infrared detectors, inductive, photoelectric, and capacitative cells, accelerometers, gyroscopes, and more. So, when you have an IoT device that will show you the wrong temperature, once you could be informed that your building was burned
upvoted 1 times
...
Tammy007
3 years, 6 months ago
Read all the comments and most suggesting A here but everyone missed "after a vulnerability has been discovered". Just because of this I will go with B
upvoted 2 times
...
KenCW
3 years, 11 months ago
A or B. Really hard to choose. I would go for 'A' since the question said it is GREATEST ongoing risk. I can just stop tight integration with other devices but updates and patches is an ongoing risk.
upvoted 1 times
...
Freddie26
4 years, 1 month ago
What does "Tight integration to existing systems" mean? That is extremely vague.
upvoted 3 times
...
malexuaa
4 years, 3 months ago
here are many instances of applications and devices (peripheraldevices especially) that remain on sale with serious known vulnerabilities in firmwareor drivers and no prospect of vendor supportfor a fix. The problem is also noticeablein consumer-grade networking appliances and in the Internet of Things (IoT). So i think its A. There will be difficulty in firmware updates.
upvoted 1 times
...
Joker20
4 years, 4 months ago
Jan 24, 2020 why we always see this date no one take exam after this date ??
upvoted 7 times
Vishal_Gajul
4 years, 3 months ago
ill be giving my exam this week soon so you will hear lol
upvoted 5 times
Diablo21
4 years, 3 months ago
same 2 weeks from today,will replay if I get some of the questions
upvoted 2 times
jackoffson9
4 years ago
You never came back. Where are you @Diablo21
upvoted 2 times
Figekioki
3 years, 11 months ago
They never come back. They don't take the exam. The exam takes them.
upvoted 10 times
...
...
...
[Removed]
4 years, 2 months ago
How was it Vishal. Did this website help?
upvoted 1 times
...
...
...
vi2
4 years, 4 months ago
Both A and B are viable. Word play here makes it a 50/50. Honestly, whoever greenlights these questions needs their heads examining.
upvoted 4 times
Dion79
4 years, 1 month ago
Completely agree. I'm go with the given answer, only reason is because, "Integrated peripherals such as cameras or microphones could be compromised to facilitate surveillance". COM501B - The Official CompTIA Security+ Study Guide Then right below the above statement I find this... lolol Pick A or B... thats some tricky of words.... Take the exam in two weeks. Still studying.. "Home automation products often use vendor-specific software and networking protocols. As with embedded devices, security features can be poorly documented, and patch management/security response processes of vendors can be inadequate".
upvoted 1 times
...
...
babati
4 years, 9 months ago
Many embedded systems use low-cost firmware chips and the vendor never produces updates to fix security problems or only produces updates for a relatively short product cycle (while the device could remain in operational use for much longer). Many embedded systems require manual updates, which are perceived as too time-consuming for a security department with other priorities to perform. Vulnerability can be used to get access to other interconnected systems, however..
upvoted 1 times
...
babati
4 years, 9 months ago
Many embedded systems use low-cost firmware chips and the vendor never produces updates to fix security problems or only produces updates for a relatively short product cycle (while the device could remain in operational use for much longer). Many embedded systems require manual updates, which are perceived as too time-consuming for a security department with other priorities to perform.
upvoted 2 times
...
vaxakaw829
4 years, 9 months ago
Folks, just remember the Mirai case (mentioned previous questions) where exploited IoTs (cameras) used to crash systems via DDoS. I guess this will help us to make a judgement fair enough.
upvoted 1 times
...
Hemonie
4 years, 9 months ago
Question says after vulnerability has been identified, meaning its either they have seen that the system is vulnerable to attacks also, which is the greatest security risk in my opinion but after that what is the next risk, answer should be B
upvoted 1 times
...
mfombi
4 years, 10 months ago
The risk is in tightly intergrating an unpatchable device into the system. So B is the correct answer.
upvoted 2 times
Bennie
4 years, 10 months ago
Yes, the weakest link is the risk!
upvoted 1 times
...
...
AllenFox
4 years, 10 months ago
I think it should be A. https://techbeacon.com/security/iot-devices-are-hard-patch-heres-why-how
upvoted 1 times
...
[Removed]
4 years, 10 months ago
the answer B.. if you have many IoT in a house connected to Alexa or Google and those failed. the whole thing will fail. a light bulb can be a IoT, i dont need that needs much patching. "Alexa turn off the lights" if Alexa doesnt work, the whole system is broken so "tight integration": seems good to me.
upvoted 7 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...