An IoT device uses the MQTT protocol without any authentication or encryption. An attacker on the same network subscribes to all topics on the MQTT broker. Which of the following is the MOST effective immediate countermeasure?
Implementing client authentication ensures that only authorized IoT devices can connect to the MQTT broker, preventing unauthorized actors from publishing or subscribing to sensitive data streams. Concurrently, enabling TLS encryption secures the communication channel itself, protecting all data transmitted between devices and the broker from eavesdropping, tampering, and man-in-the-middle attacks. This combination establishes robust confidentiality, integrity, and access control for MQTT communications, directly addressing the core security vulnerabilities.
Why this answer
The vulnerability is that the MQTT broker accepts connections from anyone (no authentication) and transmits data in cleartext (no encryption), allowing an attacker to subscribe to all topics. Implementing client authentication (username/password or client certificates) prevents unauthorized subscriptions, while enabling TLS encrypts the payload and credentials in transit. Together these directly close the two gaps that let the attacker eavesdrop.
Exam trap
CEH often tests the misconception that changing default topic names or using a VPN is sufficient to secure MQTT, when the core issue is missing authentication and encryption at the protocol level.
How to eliminate wrong answers
Option A is wrong because replacing MQTT with HTTP does not inherently add authentication or encryption and abandons a purpose-built IoT protocol without addressing the root cause. Option C is wrong because obfuscating topic names is security through obscurity; an attacker who can subscribe to all topics will still see the obfuscated names and their contents. Option D is wrong because a VPN only encrypts traffic between endpoints and does not authenticate MQTT clients to the broker, so an attacker already on the same network segment could still subscribe.