
EC-CouncilDevSecOps Essentials
Domain 5Objective 1
Integrating Threat Modeling in the Plan Stage DSE Practice Questions (Page 8)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 36–39
- 36
A DevSecOps team is planning a new feature that will handle personal data. The compliance officer requires that threat modeling be integrated into the plan stage, but the team is already overloaded. The team lead wants to minimize the impact on the team's workload while still meeting the compliance requirement. What is the best approach?
Select an answer first - 37
When should threat modeling activities be incorporated into the DevSecOps pipeline?
Select an answer first - 38
Which threat modeling methodology categorizes threats into categories such as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
Select an answer first - 39
A company is adopting DevSecOps and wants to introduce threat modeling in the plan stage. The security manager needs to justify the investment to management. Which benefit of threat modeling should the manager emphasize?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to DSE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.