
EC-CouncilDevSecOps Essentials
Domain 5Objective 1
Integrating Threat Modeling in the Plan Stage DSE Practice Questions (Page 5)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 21–25
- 21
A threat modeling session has just concluded, and the team has identified several threats and agreed on mitigations. What is the most important next step to ensure the mitigations are implemented?
Select an answer first - 22
A security team is evaluating threat modeling tools for a project that uses a microservices architecture. They need a tool that can automatically generate threat models from the architecture diagrams and support continuous updates as the architecture evolves. Which tool feature is most important?
Select an answer first - 23
A DevSecOps team is planning a new feature that will allow users to upload profile pictures. The team wants to conduct a quick threat-modeling exercise during the sprint planning meeting. Which activity is most appropriate for this time-boxed session?
Select an answer first - 24
A company is moving from a waterfall to a DevSecOps model. The security team is used to doing threat modeling at the end of the design phase. The new DevSecOps lead wants to integrate threat modeling into the plan stage. What is the most important change to make?
Select an answer first - 25
Which of the following is an effective way to communicate identified threats to relevant team members?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.