AXIS Risk Management & Mitigation 3 โ Questions and Answers
Question 1: An AXIS technician discovers that a camera stream is being intercepted on the LAN. Which technology would MOST directly prevent this type of eavesdropping?
- Enabling RTSP over TLS (RTSPS) (Correct answer)
- Applying a strong admin password
- Enabling motion detection
- Restricting PTZ control access
Correct answer: Enabling RTSP over TLS (RTSPS)
RTSP over TLS encrypts the video stream in transit, preventing plaintext interception by anyone on the same network segment.
Question 2: What does a 'residual risk' represent after security controls have been applied to an AXIS surveillance system?
- The risk that has been fully eliminated by controls
- The risk remaining after all mitigations are in place (Correct answer)
- The cost of implementing the security controls
- The original risk before any assessment was performed
Correct answer: The risk remaining after all mitigations are in place
Residual risk is the remaining exposure after all chosen security controls and mitigations have been implemented.
Question 3: Which vulnerability in older AXIS camera firmware is MOST commonly exploited in supply-chain or third-party integration scenarios?
- Use of self-signed TLS certificates
- Hard-coded default credentials not changed at deployment (Correct answer)
- Lack of motion detection calibration
- Missing ONVIF Profile S support
Correct answer: Hard-coded default credentials not changed at deployment
Hard-coded or unchanged default credentials are one of the most frequently exploited vulnerabilities in IoT deployments, including third-party integrations that retain factory defaults.
Question 4: A physical security audit reveals that an outdoor AXIS camera enclosure can be opened without tools. Which risk category does this PRIMARILY represent?
- Cyber risk
- Operational risk
- Physical tamper risk (Correct answer)
- Regulatory compliance risk
Correct answer: Physical tamper risk
An enclosure accessible without tools exposes internal hardware to direct physical manipulation, which is classified as a physical tamper risk.
Question 5: AXIS CEVD (Coordinated External Vulnerability Disclosure) is a program designed to:
- Automatically patch cameras over the air
- Allow external researchers to report vulnerabilities responsibly (Correct answer)
- Distribute firmware signatures to resellers
- Monitor network traffic for anomalies
Correct answer: Allow external researchers to report vulnerabilities responsibly
AXIS CEVD provides a structured channel for security researchers to report vulnerabilities to AXIS before public disclosure, enabling coordinated patching.
Question 6: In risk management terminology, what is the relationship between 'threat,' 'vulnerability,' and 'risk'?
- Risk = Threat ร Vulnerability ร Asset Value (Correct answer)
- Risk = Vulnerability - Threat + Control
- Risk = Threat + Asset Value only
- Risk = Control effectiveness รท Vulnerability
Correct answer: Risk = Threat ร Vulnerability ร Asset Value
Risk is commonly expressed as the product of threat likelihood, vulnerability severity, and the value of the asset at stake.
Question 7: When replacing a failed AXIS camera in a high-security environment, which practice BEST mitigates supply chain risk during the swap?
- Reuse the previous camera's IP address immediately
- Verify firmware signature and factory-reset before installation (Correct answer)
- Copy configuration from the failed unit before discarding it
- Connect the replacement to a test VLAN permanently
Correct answer: Verify firmware signature and factory-reset before installation
Verifying the firmware cryptographic signature and performing a factory reset before installation ensures the replacement device hasn't been tampered with in the supply chain.
An AXIS technician discovers that a camera stream is being intercepted on the LAN.
Which technology would MOST directly prevent this type of eavesdropping?