
EC-CouncilDevSecOps Essentials
Domain 5Objective 1
Integrating Threat Modeling in the Plan Stage DSE Practice Questions (Page 7)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 31–35
- 31
A team is conducting a threat modeling exercise for a new online payment system. They have identified the assets, created data flow diagrams, and enumerated potential threats. What is the next step in the threat modeling process?
Select an answer first - 32
After a threat-modeling session, a security analyst has identified a critical threat in a new authentication service. The team uses a Scrum process. What is the most effective way to communicate the threat and its mitigation to the development team so it is actually addressed?
Select an answer first - 33
A DevSecOps team is selecting a threat modeling tool for their organization. They need a tool that supports multiple methodologies, provides a central repository for threat models, and integrates with their existing development tools. Which tool should they choose?
Select an answer first - 34
Who should be involved in threat modeling activities during the plan stage?
Select an answer first - 35
A DevSecOps team is about to start the plan stage for a new microservices-based application. The security lead wants to ensure that threat modeling is integrated early and effectively. Which action best aligns with integrating threat modeling into the plan stage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.