312-50 exam dumps

312-50 practice question 417 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 417

Single answer▪ IoT Attack Countermeasures

A hospital is deploying internet-connected infusion pumps and patient monitoring sensors on its clinical network. During a security assessment, you discover that several devices still use default credentials, expose unnecessary management services, and communicate with a cloud dashboard over unencrypted channels. The biomedical engineering team says the devices cannot support traditional endpoint security agents and must remain operational. Which countermeasure would MOST effectively reduce the risk of compromise while preserving device availability?

  1. A

    Place all IoT medical devices on a dedicated network segment with strict ACLs, disable unused services, change default credentials, and require encrypted management and telemetry communications

  2. B

    Install a host-based antivirus and personal firewall suite directly on each infusion pump and sensor to block malware and unauthorized access

  3. C

    Allow the devices to remain on the flat clinical network, but enable MAC filtering on the switch ports because MAC addresses cannot be spoofed easily

  4. D

    Expose device web interfaces to the internet through port forwarding so vendor support can patch them faster when issues are reported

Show answer and explanation

Correct answer: A

Explanation

The best answer is to apply layered compensating controls tailored for IoT and operationally sensitive devices. In real environments, especially healthcare, many IoT and embedded devices cannot support endpoint protection agents. As a result, defenders rely on hardening and network-based controls: segment IoT devices into dedicated VLANs or microsegments, apply least-privilege ACLs, remove or disable unnecessary services, eliminate default credentials, and require encrypted communications such as TLS for management and telemetry. These practices align with common guidance from NIST IoT cybersecurity recommendations, NIST SP 800-82 principles for operational technology style environments, and general medical device security best practices from regulators and manufacturers. The other options reflect common misconceptions: agent-based controls are often not feasible on embedded devices, MAC filtering is not a strong security boundary, and directly exposing device management interfaces to the internet significantly increases risk.

  • A. Correct.

    Correct. This is the most effective and realistic IoT countermeasure set for constrained medical devices. Network segmentation limits lateral movement, ACLs restrict communications to only required systems, disabling unused services reduces attack surface, changing default credentials prevents trivial compromise, and enforcing encrypted management and telemetry protects sensitive data and credentials in transit. These are standard compensating controls for IoT and medical devices that cannot run traditional endpoint agents.

  • B. Incorrect.

    Incorrect. Many IoT and embedded medical devices do not support conventional host-based antivirus or personal firewall software due to limited resources, vendor restrictions, or regulatory validation requirements. This option also ignores the identified risks of default credentials, unnecessary services, and unencrypted communications.

  • C. Incorrect.

    Incorrect. MAC filtering is a weak control because MAC addresses can be spoofed. Keeping vulnerable IoT devices on a flat clinical network also fails to contain compromise or lateral movement. Candidates may choose this because it sounds like an access control measure, but it is not sufficient as a primary countermeasure for IoT security.

  • D. Incorrect.

    Incorrect. Internet exposure through port forwarding increases the attack surface and is contrary to secure-by-design principles. Remote vendor access, if needed, should be tightly controlled through secure remote access methods such as VPN, jump hosts, strong authentication, and logging rather than direct exposure of device interfaces.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam