What Is the Main Security Concern With Low-Cost IoT Devices?

Explain common threat vectors and attack surfaces. Given a scenario, apply common security techniques to computing resources.
Answer Correct answer: D — Low-cost IoT devices often store and forward collected data with weak or absent protections, making data storage the primary security concern.

Which of the following is most likely a security concern when installing and using low-cost IoT devices in infrastructure environments?

  1. Country of origin
  2. Device responsiveness
  3. Ease of deployment
  4. Storage of data Correct Answer

Community Votes

D
70%
A
30%

70% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

You must distinguish a real, device-level security concern from operational or geopolitical factors; the trap is choosing 'country of origin' because supply-chain headlines make it feel like the safest-sounding answer.

Low-cost IoT devices installed in infrastructure environments create their most direct security risk through how the data they collect and transmit is stored and protected. The question tests whether you can separate that genuine confidentiality concern from supply-chain, performance, and usability factors, and the answer is storage of data (D).

Selecting A (country of origin). It sounds sophisticated and echoes supply-chain risk discussions, but it is a vendor/procurement consideration that applies to any product, not the technical security concern raised by installing and operating a low-cost IoT device, and it ignores why cheap IoT gear is dangerous: weak default protections around the data it collects, stores, and ships to vendor clouds.

Community Discussion (4 comments)

iliecomptia 👍 6 Selected: D
From CompTIA guide: The sheer volume of data generated by IoT devices can make securing and protecting sensitive information difficult. As more devices are connected to the Internet, there is an increasing risk of data breaches and cyberattacks, which can result in the theft of personal and sensitive data. A- does not make sense. B&C are not security concerns but rather performance concerns.
MarysSon 👍 1 Selected: A
The question is not about storage. Storage devices are a small subset of IoT devices. Country of origin is a more pressing concern, particularly for organizations that need to protect intellectual property or classified information. Devices from hostile countries can be engineered to steal information or plant viruses.
9149f41 👍 1 Selected: D
Storage of data: This is a critical security concern. Low-cost IoT devices often lack robust security features, making them vulnerable to data breaches, unauthorized access, or misuse of sensitive information. Poorly secured data storage can lead to significant risks in infrastructure environments.
musaabokisec 👍 2 Selected: A
Chat GPT A. Country of origin Explanation: The country of origin of low-cost IoT devices is often a major security concern, especially in critical infrastructure environments. Devices manufactured in certain countries may pose risks due to: Supply chain vulnerabilities: Devices could include backdoors, malicious firmware, or compromised components. Lack of regulatory oversight: Low-cost devices may not comply with international security standards. Potential espionage: Some governments may influence manufacturers in their countries to include mechanisms for surveillance or data collection. Poor security practices: Devices from some sources may have weak default configurations, such as hardcoded credentials or unpatched vulnerabilities. These risks make the country of origin a critical factor when evaluating the security of IoT devices for infrastructure environments.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Low-cost IoT devices are built to a price point, which usually means minimal security engineering: no encryption for locally cached data, unauthenticated or weakly authenticated APIs, and telemetry streamed to a vendor-run cloud the organization does not control. The question asks for the security concern that arises "when installing and using" these devices in infrastructure, which points squarely at what happens to the sensitive data they collect, store, and forward — a confidentiality and data-protection problem. CompTIA's own IoT guidance, quoted by iliecomptia, stresses that the sheer volume of data generated by IoT devices makes protecting sensitive information difficult and increases breach exposure. Because that data can include facility telemetry, badge or sensor readings, or even video, insecure storage (D) is the concrete, exam-defensible security concern rather than a procurement or performance issue.

Why the Other Options Are Wrong

A (country of origin) is a supply-chain and third-party risk consideration that belongs to vendor due-diligence discussions; it is not a technical control gap you fix by configuring the device, and it applies equally to expensive hardware from the same region. B (device responsiveness) is a performance and availability attribute, and as iliecomptia put it, "B&C are not security concerns but rather performance concerns." C (ease of deployment) is actually a selling point of low-cost IoT — quick plug-and-play onboarding — and ease of deployment only becomes a security problem when it implies unchanged default credentials, which is not what the option states. None of these three describes a data-protection exposure in the way D does.

Community Comment Notes

The community split roughly 70/30 in favor of D, and the reasoning on the winning side matches the CompTIA study material rather than a guess: iliecomptia cites the official text on IoT data volume and explicitly labels B and C as performance topics, which is the cleanest justification on the page. musaabokisec argued for A using a pasted chatbot answer about supply-chain backdoors and malicious firmware; the underlying supply-chain idea is real, but it answers a procurement-risk question, not this one. MarysSon countered that "The question is not about storage" and that "Country of origin is a more pressing concern" for protecting intellectual property, while 9149f41 called poor data storage "a critical security concern" for cheap, weakly secured devices. Weighing the wording of the stem — installing and using low-cost IoT in infrastructure — the data-handling risk (D) is the strongest reading.

Official Reference

Exam Strategy

When a Security+ stem asks for "most likely a security concern," eliminate options that describe performance, usability, or procurement attributes before comparing the remaining candidates. Ask yourself which option maps to a CIA triad impact on enterprise data, and prefer the one describing how data is protected, stored, or transmitted.

Frequently Asked Questions

Why is country of origin not the best answer for low-cost IoT devices?

Country of origin is a supply-chain and vendor due-diligence factor that applies to any product, not a technical exposure created by installing and running a cheap IoT device in your infrastructure.

How do low-cost IoT devices put enterprise data at risk?

Many ship with weak defaults and no encryption for data at rest, and they often forward telemetry to vendor cloud services, exposing sensitive readings to unauthorized access or misuse.

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide