Which TWO of the following are common weaknesses in IoT devices that are often exploited by attackers?
The prevalence of default or hard-coded credentials represents a severe and common weakness in IoT devices. Many manufacturers ship devices with easily guessable default usernames and passwords (e.g., 'admin/admin', 'root/password') or embed unchangeable credentials directly into the firmware. Attackers frequently exploit these known credentials through automated scanning and brute-force attacks, gaining unauthorized access to devices, which can then be used for botnets, data exfiltration, or further network penetration.
Why this answer
Option C is correct because many IoT devices ship with factory-default or hard-coded credentials (e.g., admin/admin, root/root) that users never change, giving attackers trivial access via services like Telnet or SSH on ports 23/22. Option D is correct because IoT devices frequently run lightweight protocols such as MQTT, CoAP, or HTTP without TLS encryption, allowing attackers to eavesdrop on, tamper with, or inject messages on the network. Options A and B are incorrect because hardware security modules and secure boot are security hardening measures that protect keys and verify firmware integrity, not weaknesses.
Option E is incorrect because firmware updates signed with cryptographic signatures are a security best practice that prevents malicious or tampered firmware from being installed, rather than a common exploitable weakness.
Exam trap
EC-Council often tests the distinction between security controls (HSM, secure boot, signed updates) and actual vulnerabilities (default credentials, cleartext protocols), so candidates mistakenly select secure features as weaknesses.