
EC-CouncilDevSecOps Essentials
Domain 5Objective 1
Integrating Threat Modeling in the Plan Stage DSE Practice Questions (Page 1)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 1–5
- 1
After a threat modeling session, the team has identified a high-risk threat that requires a significant architectural change to mitigate. The product owner is reluctant to approve the change because it will delay the release. The security lead needs to communicate the threat effectively to the product owner. What is the most effective approach?
Select an answer first - 2
After a threat modeling session, a security analyst needs to communicate the identified threats and mitigations to the development team. Which approach is most effective for ensuring the team understands and acts on the findings?
Select an answer first - 3
Which of the following is a typical step in a threat modeling process?
Select an answer first - 4
Which benefit is most directly associated with integrating threat modeling into the plan stage of a DevSecOps pipeline?
Select an answer first - 5
A DevSecOps team is evaluating threat modeling tools. They need a tool that can be used by both security analysts and developers, supports sharing threat models across teams, and can integrate with their issue tracker. Which tool feature is most important to evaluate first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.