ISO/IEC 27402:2023 - IoT Security and Privacy Device Baseline Requirements Auditor Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

During an audit of a newly developed smart environmental sensor designed for residential use, an auditor is tasked with verifying compliance with ISO/IEC 27402:2023. The device collects ambient temperature, humidity, and occupancy data, which is transmitted to a cloud service for analysis and user access. The auditor discovers that the device\'s default firmware configuration retains raw sensor logs, including timestamps and unique device identifiers, for an indefinite period. What is the most critical finding an auditor must document regarding the device\'s adherence to the baseline requirements for data retention and minimization?

The device's default configuration retains raw sensor logs indefinitely, failing to implement a mechanism for automatic purging or anonymization of sensitive personal data as required by the standard.
The device transmits raw sensor logs to a cloud service without explicit user consent for data processing, which is a violation of privacy principles.
The device's firmware does not offer granular user controls for disabling specific sensor functions, limiting user autonomy over data collection.
The device's encryption protocols for data transmission are outdated, posing a risk to data confidentiality during transit.

About the ISO/IEC 27402:2023 - IoT Security and Privacy Device Baseline Requirements Auditor Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27402:2023 - IoT Security and Privacy Device Baseline Requirements Auditor exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.