312-50 exam dumps

312-50 practice question 418 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 418

Single answer▪ IoT Attack Countermeasures

A hospital is deploying hundreds of IP-enabled infusion pumps and patient monitors on its clinical network. During a security assessment, you discover that many devices expose unnecessary services, use default credentials, and communicate with backend systems over an unsegmented VLAN shared with employee workstations. The biomedical engineering team says the devices cannot support traditional endpoint security agents. Which countermeasure would MOST effectively reduce the risk of compromise and lateral movement while preserving device functionality?

  1. A

    Place the IoT medical devices on a dedicated network segment with strict ACLs/firewall rules, disable unused services, and enforce unique credential changes through centralized device management where supported

  2. B

    Install full-featured EDR agents on each medical device and allow unrestricted communication so monitoring tools can observe all traffic patterns

  3. C

    Rely primarily on NAT at the network edge to hide the medical devices from attackers and keep the existing flat internal network unchanged

  4. D

    Permit the devices to remain on the employee VLAN, but require staff to use complex passwords on their workstations to compensate for the device weaknesses

Show answer and explanation

Correct answer: A

Explanation

In IoT environments, especially healthcare and operational settings, many devices cannot support conventional endpoint protections. CEH candidates should recognize that compensating controls are critical: network segmentation, least-privilege communication rules, disabling unused services, changing default credentials, and centralized management where available are among the most effective countermeasures. Guidance from NIST IoT cybersecurity resources and common healthcare security best practices emphasizes isolating medical/IoT devices, minimizing exposed services, and restricting communications to required systems only. These measures directly address both initial compromise risk and post-compromise lateral movement, which are major concerns in flat enterprise networks.

  • A. Correct.

    Correct. For IoT and embedded medical devices that often cannot run host-based security tools, the most effective control is compensating network and configuration hardening. Segmenting devices into a dedicated VLAN or micro-segment, applying ACLs/firewall policies to allow only required protocols and destinations, disabling unnecessary services, and replacing default credentials are core IoT countermeasures. This reduces both the attack surface and the chance of lateral movement from compromised user endpoints or between devices.

  • B. Incorrect.

    Incorrect. Many IoT and medical devices do not support traditional EDR or host agents because of limited resources, vendor restrictions, or regulatory support constraints. Also, allowing unrestricted communication weakens security rather than improving it. Monitoring is useful, but it does not replace segmentation and service reduction.

  • C. Incorrect.

    Incorrect. NAT is not a meaningful internal security boundary and does not stop lateral movement inside a flat network. Attackers who gain access to the internal environment can still reach devices on the shared VLAN. This option reflects the common misconception that address translation is equivalent to segmentation or access control.

  • D. Incorrect.

    Incorrect. Strong workstation passwords help protect user endpoints, but they do not mitigate insecure IoT device configurations such as default credentials, exposed services, or unrestricted east-west traffic. Leaving vulnerable devices on the same VLAN as employee systems preserves a large attack surface and facilitates pivoting.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam