Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 7Objective 3

Threat Modeling and Vulnerability Assessment CSE Practice Questions (Page 10)

Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
6concepts

Questions 46–48

  1. 46foundation · easy

    Which threat modeling framework categorizes threats as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?

    Select an answer first
  2. 47expert · hard

    A security architect is choosing a threat modeling methodology for a cloud-native application that uses serverless functions, managed databases, and API gateways. The team needs to identify threats early in the development lifecycle and also assess the risk of each threat. Which methodology is best suited for this scenario?

    Select an answer first
  3. 48application · medium

    A cloud architect is using the PASTA threat modeling methodology to assess a new microservices-based application. The team has already defined the scope and identified potential attack vectors. What is the next step in the PASTA process?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.