AXIS Risk Management & Mitigation 2 — Questions and Answers
Question 1: When conducting a risk assessment for an AXIS network video surveillance deployment, what is the FIRST step in the process?
- Implement firewall rules
- Identify and inventory all assets in scope (Correct answer)
- Apply firmware updates to all cameras
- Configure HTTPS on all devices
Correct answer: Identify and inventory all assets in scope
Asset identification and inventory is always the first step in a risk assessment because you cannot protect or evaluate risk for assets you don't know exist.
Question 2: An AXIS camera is discovered on a network segment shared with corporate workstations. Which mitigation strategy BEST reduces lateral movement risk?
- Enable HTTPS on the camera
- Move the camera to a dedicated VLAN (Correct answer)
- Change the camera's default password
- Enable IEEE 802.1X on the workstations
Correct answer: Move the camera to a dedicated VLAN
Placing cameras on a dedicated VLAN network-segments IoT devices from corporate endpoints, limiting an attacker's ability to pivot from a compromised camera to workstations.
Question 3: Which threat is MOST effectively mitigated by enabling IEEE 802.1X port-based authentication on switch ports connected to AXIS cameras?
- Brute-force credential attacks on the camera web interface
- Unauthorized physical replacement of a camera with a rogue device (Correct answer)
- Man-in-the-middle interception of video streams
- Denial-of-service floods targeting camera CPU
Correct answer: Unauthorized physical replacement of a camera with a rogue device
IEEE 802.1X ensures that only authenticated devices can communicate on the network, so a rogue device plugged into a camera port cannot gain network access.
Question 4: A risk register entry shows 'likelihood: high, impact: low.' What is the MOST appropriate response strategy for this risk in an AXIS deployment?
- Avoid the risk by removing the system component
- Transfer the risk to a third-party insurer
- Accept the risk with monitoring controls in place (Correct answer)
- Immediately escalate to critical priority remediation
Correct answer: Accept the risk with monitoring controls in place
High-likelihood, low-impact risks are typically accepted with monitoring because remediation cost often exceeds potential loss.
Question 5: AXIS recommends disabling unused services and ports on cameras as a hardening measure. This practice directly reduces which attack surface component?
- Data in transit exposure
- Physical tampering vectors
- Network-accessible entry points (Correct answer)
- Firmware supply chain risk
Correct answer: Network-accessible entry points
Disabling unused services removes listening ports and protocols, shrinking the set of network entry points an attacker can exploit.
Question 6: Which AXIS feature allows administrators to detect if a camera's firmware has been tampered with before boot?
- AXIS Guardian
- Signed firmware with Secure Boot (Correct answer)
- AXIS Camera Station audit log
- HTTPS certificate pinning
Correct answer: Signed firmware with Secure Boot
Signed firmware combined with Secure Boot verifies cryptographic signatures before executing code, detecting any unauthorized firmware modification.
Question 7: During a risk treatment meeting, the team decides to purchase cyber-liability insurance for the video surveillance infrastructure. This represents which risk treatment option?
- Risk avoidance
- Risk acceptance
- Risk transfer (Correct answer)
- Risk reduction
Correct answer: Risk transfer
Purchasing insurance transfers the financial consequences of a risk event to the insurer, which is the definition of risk transfer.
When conducting a risk assessment for an AXIS network video surveillance deployment, what is the FIRST step in the process?