Courseiva
Wireless, IoT and Cloud SecuritymediumMultiple SelectObjective-mapped

CEH Wireless, IoT and Cloud Security Practice Question

Which THREE of the following are best practices for securing IoT devices in a home automation network?

⚠ Common exam trap

EC-Council often tests the misconception that UPnP simplifies integration and is safe, when in fact it is a well-known security risk due to its lack of authentication and automatic port forwarding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Segment IoT devices on a separate VLAN or subnet.

Segmenting IoT devices on a separate VLAN or subnet (Option B) is a best practice because it isolates potentially insecure IoT devices from the main trusted network. If an IoT device is compromised, the attacker cannot easily pivot to other devices on the primary LAN. This leverages Layer 2 or Layer 3 segmentation to enforce network access controls, reducing the attack surface in a home automation environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable Universal Plug and Play (UPnP) for easy integration.

    Why it's wrong here

    Enabling Universal Plug and Play (UPnP) for IoT devices is a significant security risk and should be avoided. UPnP allows devices to automatically discover each other and open ports on a router without user intervention, effectively bypassing firewall rules. This creates direct pathways from the internet to potentially vulnerable IoT devices, making them easily discoverable and exploitable by attackers scanning for open ports.

  • Segment IoT devices on a separate VLAN or subnet.

    Why this is correct

    Segmenting IoT devices onto a separate Virtual Local Area Network (VLAN) or subnet is a critical security best practice. This isolation prevents an attacker who successfully compromises an IoT device from easily moving laterally to other, more sensitive parts of the network, such as corporate servers or personal computers. By containing potential breaches within a dedicated segment, the overall impact of an attack is significantly reduced.

  • Change default usernames and passwords.

    Why this is correct

    Changing default usernames and passwords on IoT devices is a fundamental and essential security measure. Manufacturers often ship devices with easily guessable or publicly known default credentials, which are frequently targeted by automated scanning tools and botnets. Replacing these with strong, unique passwords immediately removes a common and easily exploitable attack vector, preventing unauthorized access and control of the device.

  • Disable unnecessary features and services.

    Why this is correct

    Disabling unnecessary features and services on IoT devices is crucial for minimizing their attack surface. Every active feature, service, or open port represents a potential vulnerability that an attacker could exploit to gain unauthorized access or control. By deactivating components not essential for the device's intended function, organizations reduce the number of potential entry points available to adversaries, thereby enhancing the device's security posture.

  • Ensure all devices are connected directly to the internet for remote access.

    Why it's wrong here

    Connecting all IoT devices directly to the internet for remote access without an intermediary secure gateway is a dangerous practice. Direct exposure makes devices highly vulnerable to constant scanning, exploitation attempts, and denial-of-service attacks from malicious actors worldwide. A secure gateway, VPN, or cloud-based IoT platform provides essential layers of authentication, encryption, and centralized security policy enforcement, acting as a protective barrier against direct internet threats.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.