What Is the Main Security Concern With Low-Cost IoT Devices?
Which of the following is most likely a security concern when installing and using low-cost IoT devices in infrastructure environments?
Community Votes
70% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
You must distinguish a real, device-level security concern from operational or geopolitical factors; the trap is choosing 'country of origin' because supply-chain headlines make it feel like the safest-sounding answer.
Low-cost IoT devices installed in infrastructure environments create their most direct security risk through how the data they collect and transmit is stored and protected. The question tests whether you can separate that genuine confidentiality concern from supply-chain, performance, and usability factors, and the answer is storage of data (D).
Selecting A (country of origin). It sounds sophisticated and echoes supply-chain risk discussions, but it is a vendor/procurement consideration that applies to any product, not the technical security concern raised by installing and operating a low-cost IoT device, and it ignores why cheap IoT gear is dangerous: weak default protections around the data it collects, stores, and ships to vendor clouds.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Low-cost IoT devices are built to a price point, which usually means minimal security engineering: no encryption for locally cached data, unauthenticated or weakly authenticated APIs, and telemetry streamed to a vendor-run cloud the organization does not control. The question asks for the security concern that arises "when installing and using" these devices in infrastructure, which points squarely at what happens to the sensitive data they collect, store, and forward — a confidentiality and data-protection problem. CompTIA's own IoT guidance, quoted by iliecomptia, stresses that the sheer volume of data generated by IoT devices makes protecting sensitive information difficult and increases breach exposure. Because that data can include facility telemetry, badge or sensor readings, or even video, insecure storage (D) is the concrete, exam-defensible security concern rather than a procurement or performance issue.Why the Other Options Are Wrong
A (country of origin) is a supply-chain and third-party risk consideration that belongs to vendor due-diligence discussions; it is not a technical control gap you fix by configuring the device, and it applies equally to expensive hardware from the same region. B (device responsiveness) is a performance and availability attribute, and as iliecomptia put it, "B&C are not security concerns but rather performance concerns." C (ease of deployment) is actually a selling point of low-cost IoT — quick plug-and-play onboarding — and ease of deployment only becomes a security problem when it implies unchanged default credentials, which is not what the option states. None of these three describes a data-protection exposure in the way D does.Community Comment Notes
The community split roughly 70/30 in favor of D, and the reasoning on the winning side matches the CompTIA study material rather than a guess: iliecomptia cites the official text on IoT data volume and explicitly labels B and C as performance topics, which is the cleanest justification on the page. musaabokisec argued for A using a pasted chatbot answer about supply-chain backdoors and malicious firmware; the underlying supply-chain idea is real, but it answers a procurement-risk question, not this one. MarysSon countered that "The question is not about storage" and that "Country of origin is a more pressing concern" for protecting intellectual property, while 9149f41 called poor data storage "a critical security concern" for cheap, weakly secured devices. Weighing the wording of the stem — installing and using low-cost IoT in infrastructure — the data-handling risk (D) is the strongest reading.Official Reference
Exam Strategy
When a Security+ stem asks for "most likely a security concern," eliminate options that describe performance, usability, or procurement attributes before comparing the remaining candidates. Ask yourself which option maps to a CIA triad impact on enterprise data, and prefer the one describing how data is protected, stored, or transmitted.
Frequently Asked Questions
Why is country of origin not the best answer for low-cost IoT devices?
Country of origin is a supply-chain and vendor due-diligence factor that applies to any product, not a technical exposure created by installing and running a cheap IoT device in your infrastructure.
How do low-cost IoT devices put enterprise data at risk?
Many ship with weak defaults and no encryption for data at rest, and they often forward telemetry to vendor cloud services, exposing sensitive readings to unauthorized access or misuse.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →