← All CPL Flashcard Decks

Smart Lock & IoT Security Flashcards

7 cards from real CPL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Smart Lock & IoT Security flashcards as text
  1. What type of cyberattack involves an adversary positioning themselves between a smart lock and its app to intercept and potentially alter communications?

    Answer: Man-in-the-middle (MitM) attack

    A man-in-the-middle attack intercepts communications between two parties — in this case, the smart lock and its controlling app — without either party's knowledge.

  2. A locksmith discovers a smart lock is running firmware from 2019 with no updates applied. Why is this a significant security concern?

    Answer: Known vulnerabilities discovered since 2019 remain unpatched and exploitable

    Unpatched firmware contains known security vulnerabilities that attackers can exploit using publicly documented methods, making the device a weak point in the security system.

  3. Which of the following is considered a best practice for securing a smart lock's administrative credentials?

    Answer: Use a strong, unique password for the associated app account with MFA enabled

    Using a strong unique password combined with multi-factor authentication (MFA) on the app account significantly reduces the risk of unauthorized remote access.

  4. What is a 'brute force' attack in the context of a smart lock's PIN keypad?

    Answer: Systematically trying every possible PIN combination until the correct one is found

    A brute force attack on a PIN keypad involves systematically attempting every possible code combination until the correct one unlocks the device.

  5. A smart lock advertises 'end-to-end encryption.' What does this mean for the security of the lock's communications?

    Answer: Data is encrypted on the sender's device and only decrypted on the recipient's device, preventing intermediary access

    End-to-end encryption ensures that data is encrypted at the source and can only be decrypted by the intended recipient, preventing third parties — including the manufacturer's servers — from reading the data.

  6. A locksmith client reports that their smart lock was 'jammed' and temporarily stopped responding to commands. Which attack type is most likely responsible?

    Answer: Denial of Service (DoS) / RF jamming

    RF jamming or a wireless denial-of-service attack can flood a lock's communication channel or disrupt its frequency, preventing it from receiving legitimate commands.

  7. When a smart lock vendor discontinues support for an older lock model, what is the primary security risk for the end user?

    Answer: No more security patches will be issued, leaving known vulnerabilities permanently unaddressed

    End-of-life status means the vendor will no longer release security updates, so any newly discovered vulnerabilities in that firmware will never be patched.