CEH Wireless, IoT and Cloud Security Practice Question
Which THREE of the following are best practices for securing IoT devices in a home automation network?
⚠ Common exam trap
EC-Council often tests the misconception that UPnP simplifies integration and is safe, when in fact it is a well-known security risk due to its lack of authentication and automatic port forwarding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Segment IoT devices on a separate VLAN or subnet.
Segmenting IoT devices on a separate VLAN or subnet (Option B) is a best practice because it isolates potentially insecure IoT devices from the main trusted network. If an IoT device is compromised, the attacker cannot easily pivot to other devices on the primary LAN. This leverages Layer 2 or Layer 3 segmentation to enforce network access controls, reducing the attack surface in a home automation environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Universal Plug and Play (UPnP) for easy integration.
Why it's wrong here
Enabling Universal Plug and Play (UPnP) for IoT devices is a significant security risk and should be avoided. UPnP allows devices to automatically discover each other and open ports on a router without user intervention, effectively bypassing firewall rules. This creates direct pathways from the internet to potentially vulnerable IoT devices, making them easily discoverable and exploitable by attackers scanning for open ports.
- ✓
Segment IoT devices on a separate VLAN or subnet.
Why this is correct
Segmenting IoT devices onto a separate Virtual Local Area Network (VLAN) or subnet is a critical security best practice. This isolation prevents an attacker who successfully compromises an IoT device from easily moving laterally to other, more sensitive parts of the network, such as corporate servers or personal computers. By containing potential breaches within a dedicated segment, the overall impact of an attack is significantly reduced.
- ✓
Change default usernames and passwords.
Why this is correct
Changing default usernames and passwords on IoT devices is a fundamental and essential security measure. Manufacturers often ship devices with easily guessable or publicly known default credentials, which are frequently targeted by automated scanning tools and botnets. Replacing these with strong, unique passwords immediately removes a common and easily exploitable attack vector, preventing unauthorized access and control of the device.
- ✓
Disable unnecessary features and services.
Why this is correct
Disabling unnecessary features and services on IoT devices is crucial for minimizing their attack surface. Every active feature, service, or open port represents a potential vulnerability that an attacker could exploit to gain unauthorized access or control. By deactivating components not essential for the device's intended function, organizations reduce the number of potential entry points available to adversaries, thereby enhancing the device's security posture.
- ✗
Ensure all devices are connected directly to the internet for remote access.
Why it's wrong here
Connecting all IoT devices directly to the internet for remote access without an intermediary secure gateway is a dangerous practice. Direct exposure makes devices highly vulnerable to constant scanning, exploitation attempts, and denial-of-service attacks from malicious actors worldwide. A secure gateway, VPN, or cloud-based IoT platform provides essential layers of authentication, encryption, and centralized security policy enforcement, acting as a protective barrier against direct internet threats.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.