- What the ITS-110 Exam Actually Tests
- Exam Mechanics and Registration Facts
- Where the Points Live: The Seven Domains
- Domain 1 Deep Dive: Securing IoT Portals
- The Three 14% Domains
- Privacy, Firmware, and Physical Security
- How Questions Are Written and How to Read Them
- A Domain-Ordered Study Sequence
- Exam Day, Retakes, and Renewal
- Frequently Asked Questions
- The CIoTSP exam is CertNexus ITS-110: 100 multiple-choice/multiple-response questions in 120 minutes, including 10 minutes of administrative time.
- Securing IoT Portals carries 29% of the blueprint, more than any other domain, so it deserves the most study time.
- The passing score is 60% or 61% depending on the form; plan to clear it with margin.
- The voucher is $367.50 USD and includes one same-version retake within its validity window, normally 18 months.
What the ITS-110 Exam Actually Tests
The Certified Internet of Things Security Practitioner credential, issued by CertNexus, validates that you can identify and address security risks across an IoT ecosystem: the devices, the portals that manage them, the network services they depend on, the data they generate, and the people whose privacy they affect. The exam code is ITS-110, and it is built around a seven-domain blueprint (version 1.4, issued 15 January 2019 and modified 29 June 2022).
If you are still orienting yourself to the credential itself, the pages on what CIoTSP certification is and what CIoTSP stands for cover the basics. This guide assumes you have decided to sit the exam and want a practical plan for passing it the first time.
One thing sets this exam apart from general security certifications: it is scoped to IoT. You will not be asked to configure enterprise firewalls in the abstract. You will be asked how a constrained device authenticates to a cloud portal, how firmware updates should be validated before installation, or what privacy obligations attach to sensor data collected from consumers. Candidates who study only generic security material tend to find the scenario wording unfamiliar.
Exam Mechanics and Registration Facts
Knowing the logistics removes avoidable stress. Here is what is verified for the current ITS-110 offering:
| Item | Detail |
|---|---|
| Certifying body | CertNexus |
| Exam code | ITS-110 |
| Question count and format | 100 multiple-choice and multiple-response questions |
| Time allowed | 120 minutes, including 5 minutes for the candidate agreement and 5 minutes for the tutorial |
| Passing score | 60% or 61% depending on form (the older blueprint lists 60%) |
| Delivery | Pearson VUE testing centers or OnVUE online proctoring |
| Voucher price | $367.50 USD |
| Prerequisites | None formal; IoT and security familiarity recommended |
| Exam conditions | Closed book; online-proctoring requirements apply |
| Validity | Three years |
Note the time math: because 10 of the 120 minutes go to the agreement and tutorial, your effective testing window is roughly 110 minutes for 100 questions. That works out to a little over a minute per item, which is comfortable for single-answer recall questions but tighter for multiple-response items that require you to evaluate several options.
For a full pricing picture, including what the voucher covers, see the CIoTSP certification cost breakdown. For eligibility questions, the CIoTSP requirements guide explains why there is no gatekeeping on experience, and the passing score article goes deeper on the 60% versus 61% distinction.
Where the Points Live: The Seven Domains
The blueprint divides the exam into seven domains whose weights total 100%. Study time should roughly track those weights, with extra attention to your personal weak spots.
| Domain | Name | Weight |
|---|---|---|
| 1 | Securing IoT Portals | 29% |
| 2 | Implementing Authentication, Authorization, and Accounting | 14% |
| 3 | Securing Network Services | 14% |
| 4 | Securing Data | 14% |
| 5 | Addressing Privacy Concerns | 12% |
| 6 | Securing Software/Firmware | 10% |
| 7 | Enhancing Physical Security | 7% |
Domain 1 alone is worth nearly as much as Domains 5, 6, and 7 combined (29% versus 29%). That asymmetry is the single most useful fact for planning. A candidate who masters portals and the three 14% domains has already covered 71% of the exam. The full breakdown, with subtopics, is in the complete guide to the seven CIoTSP content areas.
Domain 1 Deep Dive: Securing IoT Portals
The portal is the management plane of an IoT deployment: the web or mobile interface through which administrators and users register devices, view telemetry, push configurations, and manage accounts. Because a compromised portal can expose every connected device at once, the exam treats it as the center of gravity.
Domain 1: Securing IoT Portals (29%)
Expect scenario questions about protecting web and mobile management interfaces and the APIs behind them.
- Identify common web application weaknesses that apply to device management consoles, such as injection, broken session handling, and cross-site scripting.
- Understand secure session management, including token handling, timeouts, and logout behavior.
- Recognize insecure default credentials, weak password reset flows, and account enumeration risks.
- Know how encryption in transit protects portal traffic and which configuration errors undermine it.
- Be able to evaluate the security of device registration and provisioning workflows.
- Understand how input validation, output encoding, and rate limiting reduce attack surface.
When studying this domain, think in terms of attacker goals: what would someone gain by taking over the portal, and which design flaws make that easy? The exam rewards candidates who can match a described weakness to the correct mitigation, not those who merely memorize definitions.
The Three 14% Domains
Authentication, network services, and data security each carry 14%, and together they make up 42% of the exam. They are closely related, which means studying them as a connected set is more efficient than treating them as isolated silos.
Authentication, Authorization, and Accounting (Domain 2)
Domain 2: Implementing Authentication, Authorization, and Accounting (14%)
This domain covers who or what is allowed to connect, what they may do, and how actions are recorded.
- Distinguish device authentication from user authentication, and know why constrained devices complicate both.
- Understand credential types: passwords, certificates, tokens, and keys, along with their lifecycle and rotation needs.
- Apply least privilege and role-based access concepts to IoT users and services.
- Recognize the role of accounting and logging in detecting misuse and supporting investigation.
- Understand multifactor authentication and where it is practical in an IoT context.
Securing Network Services (Domain 3)
Domain 3: Securing Network Services (14%)
IoT devices live on networks, and the exam expects you to know how to harden those communication paths.
- Identify which network services a device should and should not expose, and why unnecessary open ports are a risk.
- Understand secure protocol choices and how to configure transport security correctly.
- Apply network segmentation so a compromised device cannot reach critical systems.
- Recognize wireless and short-range communication risks specific to IoT deployments.
- Understand how monitoring and filtering detect abnormal device behavior.
Securing Data (Domain 4)
Domain 4: Securing Data (14%)
Data protection spans the full lifecycle: collection, transmission, storage, and disposal.
- Distinguish data at rest, in transit, and in use, and match each to appropriate protections.
- Understand encryption fundamentals, key management, and the consequences of poor key handling.
- Know integrity controls such as hashing and digital signatures, and what each proves.
- Recognize risks around data retention and secure disposal on decommissioned devices.
A useful study technique here is to trace a single sensor reading from the moment it is generated to the moment it is archived, listing every threat and control along the way. That one exercise touches all three domains.
Privacy, Firmware, and Physical Security
The remaining three domains total 29%. They are smaller individually, but they contain highly testable facts and often separate candidates who pass comfortably from those who scrape by.
Domain 5: Addressing Privacy Concerns (12%)
IoT devices often collect personal data passively, so privacy is a design obligation, not an afterthought.
- Understand data minimization and purpose limitation in the context of sensor and user data.
- Recognize user consent, notice, and transparency expectations for connected products.
- Be aware that privacy regulations influence how data may be collected, stored, and shared, without needing to recite statute text.
- Apply privacy-by-design thinking when evaluating a described product or deployment.
Domain 6: Securing Software/Firmware (10%)
Firmware is the code that makes a device trustworthy or exploitable.
- Understand secure update mechanisms, including signature verification before installation.
- Recognize the risks of unsigned updates, hard-coded credentials, and unpatched components.
- Know why secure boot and code integrity checks matter for resisting tampering.
- Understand vulnerability management and patch lifecycle for devices that may be hard to reach in the field.
Domain 7: Enhancing Physical Security (7%)
Unlike servers in a locked data center, IoT devices are frequently deployed in exposed locations.
- Recognize threats from physical access, such as debug ports, storage extraction, and device theft.
- Understand tamper resistance and tamper detection concepts.
- Know why disabling unused physical interfaces reduces risk.
- Consider environmental and deployment factors that affect device security.
How Questions Are Written and How to Read Them
The ITS-110 uses multiple-choice and multiple-response formats. Multiple-response items, where more than one option is correct, are the more error-prone type because partial knowledge can lead you to select one right answer and miss another. When a question asks you to choose more than one option, evaluate each option independently as true or false before you commit.
Scenario framing is common. You may read a short description of a smart building, a medical sensor network, or an industrial gateway, then be asked which control best addresses a stated weakness. Two habits help:
- Identify the layer first. Is the problem about the portal, the network, the data, the firmware, or the physical device? Naming the domain narrows the plausible answers immediately.
- Look for the best fit, not just a true statement. Distractors are often accurate in general but do not address the specific risk described.
To gauge how demanding this format feels in practice, read how hard the CIoTSP exam is and the data-focused pass rate discussion. Then take timed attempts on the CIoTSP practice test site to build pacing and recognize your own question-reading mistakes before the real thing.
A Domain-Ordered Study Sequence
Because the blueprint is weighted so unevenly, the order in which you study matters. The sequence below front-loads the heaviest domain, groups the related 14% domains together, and saves the smaller, more factual domains for later review. Adjust the length to your background; someone with a web security job may compress the first weeks, while a hardware engineer may spend longer there.
Securing IoT Portals (29%)
- Study web and API weaknesses as they apply to device management consoles.
- Walk through registration, provisioning, and session handling flows.
- Finish with a short quiz limited to Domain 1 to expose gaps early.
Authentication, Authorization, and Accounting (14%)
- Compare device and user credential types and their lifecycles.
- Map roles and least-privilege decisions to sample IoT scenarios.
- Revisit portal session topics, since authentication overlaps heavily.
Network Services and Data Security (14% each)
- Study segmentation, exposed services, and transport protection.
- Trace one sensor reading through its full data lifecycle, noting controls at each step.
- Review encryption, hashing, and signature concepts side by side.
Privacy, Firmware, and Physical Security (12%, 10%, 7%)
- Learn privacy-by-design principles and data minimization examples.
- Study secure update and boot concepts as one connected topic.
- Cover physical threats and tamper protections quickly, then drill facts.
Integration and Timed Practice
- Take full-length timed practice exams and review every miss by domain.
- Return to your weakest two domains for targeted reading.
- Use the CIoTSP cheat sheet for a final fact review.
This is a template, not a mandate. The principle that carries over to any schedule is to spend the most hours where the most points are, and to revisit portals and authentication at the end, since both appear in scenario questions that blend multiple domains. For structured materials, the CIoTSP training overview outlines your options.
Exam Day, Retakes, and Renewal
Scheduling and Delivery
You can test at a Pearson VUE center or through OnVUE online proctoring. Testing centers offer a controlled environment; online delivery offers convenience but requires a compliant room and equipment. Check the exam dates and scheduling guide for availability considerations, and book early enough that you have a realistic buffer if you need to reschedule.
The Retake Safety Net
Current policy includes one free same-version retake within the voucher's validity period, normally 18 months. That reduces the financial downside of a first-attempt miss, but it should not become a reason to underprepare. A retake still costs time and momentum, and the aim of this guide is to avoid needing one.
Renewal and Value
The credential is valid for three years. The verified renewal route is to pass the latest version of the exam before your certification expires. Note that CIoTSP does not appear on the reviewed CertNexus continuing education eligible list, so do not assume continuing education credits or a CE-only renewal fee apply to it. Confirm current renewal terms directly with CertNexus when your expiration approaches.
If you are weighing whether the investment makes sense for your career, the CIoTSP ROI analysis and the salary guide examine the question from the career side, and the CIoTSP jobs page covers the kinds of roles where IoT security skills are relevant.
Key Takeaway
Weight your preparation to the blueprint: start with Securing IoT Portals at 29%, study the three 14% domains as a connected group, and keep practice scores comfortably above the 60% to 61% threshold before booking your exam slot.
Frequently Asked Questions
The exam has 100 multiple-choice and multiple-response questions. You have 120 minutes in total, which includes five minutes for the candidate agreement and five minutes for the tutorial.
The current official page cites 60% or 61% depending on the exam form, while the older blueprint lists 60%. Because the exact threshold can vary, aim to score well above 61% on practice exams.
No. There are no formal education, experience, training-hour, reference, or prior-certification requirements. CertNexus recommends familiarity with IoT and security concepts, which makes the material considerably easier to absorb.
Start with Securing IoT Portals, which accounts for 29% of the blueprint and is the largest single domain. It also overlaps with authentication and data topics, so early mastery pays off across the rest of your study.
Current policy includes one free same-version retake within the voucher's validity period, normally 18 months. The voucher itself is priced at $367.50 USD, so confirm the retake terms with CertNexus when you purchase.