- Exam Snapshot: ITS-110 at a Glance
- The Seven-Domain Weight Map
- Domain 1: Securing IoT Portals (29%)
- Domains 2-4: AAA, Network Services, and Data (14% Each)
- Domains 5-7: Privacy, Software/Firmware, and Physical Security
- Scoring, Retakes, and Registration Mechanics
- Validity and Renewal Facts
- Sequencing Your Review by Domain Weight
- Last-Pass Checklist Before Exam Day
- Frequently Asked Questions
- The CertNexus ITS-110 exam has 100 multiple-choice/multiple-response questions in 120 minutes, including five minutes each for the agreement and tutorial.
- Securing IoT Portals carries 29% of the blueprint, more than any other domain and more than twice Securing Software/Firmware.
- Passing score is listed as 60% or 61% depending on form, so aim well above it.
- The voucher is $367.50 USD and includes one free same-version retake within its validity window, normally 18 months.
Exam Snapshot: ITS-110 at a Glance
The Certified Internet of Things Security Practitioner (CIoTSP) is issued by CertNexus, and the exam code is ITS-110. This page condenses the facts you need to hold in your head on exam day into a single scannable review. If you want the full narrative on any item, the linked deep-dive articles cover each one, starting with the CIoTSP study guide for the overall preparation plan.
| Item | What to Know |
|---|---|
| Certifying body | CertNexus |
| Exam code | ITS-110 |
| Format | 100 multiple-choice and multiple-response questions |
| Time | 120 minutes, which includes five minutes for the candidate agreement and five minutes for the tutorial |
| Delivery | Pearson VUE testing centers or OnVUE online proctoring |
| Voucher price | $367.50 USD (current) |
| Passing score | 60% or 61% depending on form; older blueprint says 60% |
| Prerequisites | None formal; IoT and security familiarity recommended |
| Blueprint | Version 1.4, issued 15 January 2019, modified 29 June 2022 |
| Book policy | Closed book; no external-calculator permission verified |
Two details deserve a second look. First, the 120 minutes is not 120 minutes of question time: ten minutes are consumed by administrative screens, leaving roughly 110 minutes for 100 questions. Second, the question mix includes multiple-response items, where more than one answer is correct. Those items punish partial knowledge, so reading the stem carefully for "select all that apply" language matters as much as knowing the content.
The Seven-Domain Weight Map
The blueprint divides the exam into seven domains totaling 100%. The distribution is lopsided: one domain holds nearly a third of the exam, three sit at 14%, and the rest taper off. For a fuller treatment of each area, see the complete guide to all 7 CIoTSP content areas.
| Domain | Weight | Approx. Questions on a 100-Item Form |
|---|---|---|
| 1. Securing IoT Portals | 29% | About 29 |
| 2. Implementing Authentication, Authorization, and Accounting | 14% | About 14 |
| 3. Securing Network Services | 14% | About 14 |
| 4. Securing Data | 14% | About 14 |
| 5. Addressing Privacy Concerns | 12% | About 12 |
| 6. Securing Software/Firmware | 10% | About 10 |
| 7. Enhancing Physical Security | 7% | About 7 |
The question counts above are simple arithmetic from the published weights on a 100-question form, not an official per-domain item count, so treat them as planning estimates. The practical message is clear: Domains 1 through 4 together account for 71% of the exam. A candidate who is strong there has a comfortable cushion even if the physical security items go badly.
Domain 1: Securing IoT Portals (29%)
This is the heaviest domain and the one where a weak spot costs the most. In an IoT context, a "portal" is the management and user-facing surface of the ecosystem: the web dashboards, mobile apps, and administrative consoles that people use to configure devices, view telemetry, and push commands. Because those interfaces sit between humans and fleets of devices, a compromise there can cascade across thousands of endpoints.
Securing IoT Portals: What to Master
Expect scenario questions that ask you to identify the weakest control in a described portal deployment, or to pick the most appropriate mitigation.
- Common web-application weaknesses as they apply to device management consoles, including injection, cross-site scripting, and broken session handling
- Secure session management, credential handling, and account recovery workflows
- Transport protection for portal traffic and the role of certificates
- Input validation and output encoding on portal and API endpoints
- Hardening administrative interfaces, including default credentials and exposed management ports
- Secure design of mobile and cloud-facing companion interfaces
Because this domain is so large, it is worth revisiting early and often. The difficulty guide explains why candidates with network backgrounds but little web-security exposure tend to find this domain the steepest climb.
Domains 2-4: AAA, Network Services, and Data (14% Each)
Domain 2: Implementing Authentication, Authorization, and Accounting
The three A's are the vocabulary of this domain, and exam items often test whether you can tell them apart in a scenario.
AAA Essentials
- Authentication: proving identity, whether for a user, a device, or a service. Know the difference between single-factor and multi-factor approaches and where certificate-based device identity fits.
- Authorization: deciding what an authenticated identity may do. Least privilege and role-based access are recurring themes.
- Accounting: logging and auditing what happened, by whom, and when, so incidents can be reconstructed.
- Device identity and credential lifecycle: provisioning, rotation, and revocation at fleet scale
Domain 3: Securing Network Services
This domain covers the communication paths between devices, gateways, and back-end services. Questions tend to ask which protocol or configuration choice reduces exposure.
Network Services Focus Areas
- Securing the protocols IoT devices use to talk to gateways and cloud platforms
- Encrypting traffic in transit and understanding where encryption is and is not applied
- Network segmentation to isolate IoT devices from critical enterprise systems
- Disabling unnecessary services and closing unused ports on devices
- Wireless considerations, including securing the links that constrained devices commonly use
Domain 4: Securing Data
Data protection spans the full lifecycle: collection at the sensor, transmission, storage, and eventual disposal.
Data Protection Essentials
- Data at rest versus data in transit, and the controls appropriate to each
- Cryptographic fundamentals: symmetric versus asymmetric, hashing, and digital signatures
- Key management basics, including storage and rotation of keys on constrained devices
- Data integrity and authenticity for sensor readings that drive automated decisions
- Secure disposal and decommissioning of devices that hold residual data
Domains 5-7: Privacy, Software/Firmware, and Physical Security
Domain 5: Addressing Privacy Concerns (12%)
IoT devices collect data about people and environments, often continuously and often without an obvious interface to explain what is happening. This domain tests whether you can recognize privacy risk and apply sensible design choices.
- What counts as personal or sensitive data in a connected-device context
- Data minimization: collect only what the function requires
- Transparency and consent mechanisms for devices with limited or no screen
- Retention, sharing with third parties, and the privacy implications of cloud analytics
- Privacy-by-design principles applied to product and deployment decisions
Domain 6: Securing Software/Firmware (10%)
Firmware is the code that runs on the device itself, and it is often the hardest thing to patch once a product ships. Questions here focus on keeping that code trustworthy over the device's life.
- Secure boot and verification of firmware authenticity before it executes
- Signed update mechanisms and protection of the update channel
- Patch and update management across a large, distributed fleet
- Secure development practices and avoiding hard-coded credentials
- Third-party and open-source component risk in embedded software
Domain 7: Enhancing Physical Security (7%)
The smallest domain, but not one to ignore. IoT devices frequently live in places attackers can touch, so physical access is part of the threat model.
- Tamper resistance and tamper detection for deployed devices
- Protecting debug interfaces and ports that expose device internals
- Secure storage of keys and secrets in hardware
- Environmental and location considerations for device placement
Key Takeaway
Even at 7%, physical security items are usually the most approachable on the exam. Treat them as reliable points to bank quickly, and spend the time you save on the heavier scenario questions in Domain 1.
Scoring, Retakes, and Registration Mechanics
The current official page lists a passing score of 60% or 61% depending on the exam form, while the older blueprint states 60%. Because the exact threshold can differ by form and you will not know which form you receive, the safe approach is to prepare for comfortably above 61% rather than aiming at the line. The passing score breakdown goes into how to interpret that range.
| Logistics Item | Fact |
|---|---|
| Voucher cost | $367.50 USD at the time of writing |
| Retake policy | One free same-version retake within voucher validity, normally 18 months |
| Testing options | Pearson VUE testing center or OnVUE online proctoring |
| Online proctoring | Online-proctoring environment and ID requirements apply |
| Reference materials | Closed book |
| Calculator | No external-calculator permission verified |
The retake provision is a real safety net, but note the phrase "same-version": the free retake applies to the same exam version, so it is worth confirming the details when you purchase. For the complete financial picture, including what the voucher does and does not cover, see the certification cost breakdown. If you are choosing between a test center and online delivery, the exam dates and scheduling guide covers how booking works.
Validity and Renewal Facts
The credential is valid for three years. The verified renewal route is to pass the latest-version exam before your certification expires. That is a meaningful distinction from some other CertNexus credentials: CIoTSP does not appear on the reviewed CertNexus continuing-education-eligible list, so do not assume that 90 CE credits or a CE-only renewal fee applies to it. Plan for retaking the current exam version instead.
Because the blueprint is currently v1.4 (issued 15 January 2019 and modified 29 June 2022), a newer version may exist by the time your renewal window arrives. Check the current exam page rather than relying on an older study resource when your three years are up.
Who Sits This Exam and Why
There are no formal education, experience, training-hours, reference, or prior-certification prerequisites. CertNexus recommends familiarity with IoT and security, which in practice means that candidates arrive from varied backgrounds: network engineers moving into connected-device work, embedded developers who need a security credential, and security analysts expanding into operational technology. The requirements article details eligibility, and the ROI analysis helps you judge whether the credential suits your goals. For earnings context, the salary guide discusses compensation qualitatively without inflated claims.
Sequencing Your Review by Domain Weight
Rather than a generic schedule, tie your calendar to the blueprint. Domain 1 deserves the earliest and most repeated attention because it carries 29%, and the three 14% domains deserve the next block because they interlock.
Securing IoT Portals
- Cover web-application weaknesses as they apply to device consoles
- Practice scenario questions that ask for the weakest control
AAA and Securing Network Services
- Drill the authentication, authorization, and accounting distinctions
- Review protocol protection and segmentation scenarios
Securing Data and Privacy
- Cryptography fundamentals and key management on constrained devices
- Data minimization and privacy-by-design scenarios
Firmware, Physical Security, and Full Review
- Secure boot, signed updates, and tamper protection
- Return to Domain 1 with timed mixed-domain practice
Adjust the pace to your own background. A web-security veteran might compress Week 1 and expand the firmware and physical material, while an embedded engineer may need the opposite. The study guide expands on how to adapt this outline.
Last-Pass Checklist Before Exam Day
- Confirm the format: 100 questions, 120 minutes including ten minutes of administrative screens.
- Recite the domain weights, starting with 29% for Securing IoT Portals.
- Be able to distinguish authentication, authorization, and accounting in a one-line scenario.
- Recall the lifecycle of data: at rest, in transit, and at disposal.
- Review secure boot and signed-update logic for firmware.
- Remember that multiple-response items may have more than one correct answer.
- Verify your ID and, for OnVUE, complete the system check ahead of time.
- Know that no external references or verified calculator are available.
Key Takeaway
Do a final timed mixed-domain set on the CIoTSP practice test site within a few days of the exam. Reviewing your misses by domain shows you whether to spend the last hours on portals, the 14% trio, or the lighter domains.
If you are still deciding whether to pursue the credential, the overview articles on what CIoTSP certification is and CIoTSP jobs give useful framing. Once you are ready to test your recall under realistic conditions, the practice exams are the quickest way to find your weak domains.
Frequently Asked Questions
The exam has 100 multiple-choice and multiple-response questions. You have 120 minutes total, which includes five minutes for the candidate agreement and five minutes for the tutorial, leaving about 110 minutes of working time.
Securing IoT Portals, which carries 29% of the blueprint, is the largest domain. After that, Authentication, Authorization, and Accounting, Securing Network Services, and Securing Data each carry 14%, so together those four domains make up 71% of the exam.
The current official page lists 60% or 61% depending on the exam form, and the older blueprint states 60%. Since you may not know which form you will receive, prepare to score comfortably above that range.
Current policy includes one free same-version retake within the voucher validity period, normally 18 months. Confirm the specific terms when you purchase your $367.50 voucher.
The certification is valid for three years, and the verified renewal route is passing the latest-version exam before expiration. CIoTSP is not on the reviewed CertNexus CE-eligible list, so do not assume a continuing-education credit renewal applies.