Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 2Objective 1

Threat Modeling Concepts ECDE Practice Questions (Page 1)

Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.

35questions here
7free pages
5concepts

Questions 1–5

  1. 1expert · hard

    A DevSecOps team is threat modeling a legacy system that is being migrated to the cloud. They have limited knowledge of the system's architecture. What is the first step they should take?

    Select an answer first
  2. 2foundation · easy

    How does threat modeling integrate into a DevSecOps pipeline to support continuous security?

    Select an answer first
  3. 3foundation · easy

    Which threat modeling methodology is primarily focused on classifying threats into categories such as Spoofing, Tampering, and Repudiation?

    Select an answer first
  4. 4expert · hard

    A team is threat modeling a new online banking application. They have completed the system decomposition and identified threats using STRIDE. They are now at the mitigation planning stage. What should they do to ensure the mitigations are effective?

    Select an answer first
  5. 5application · medium

    A startup is building a mobile app that handles health data. They want to integrate security early in the SDLC. The CTO asks the DevSecOps engineer to explain why threat modeling is valuable at this stage. Which statement best explains the purpose of threat modeling in the SDLC?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.