
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 1
Threat Modeling Concepts ECDE Practice Questions (Page 2)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
35questions here
7free pages
5concepts
Questions 6–10
- 6
A developer asks why the team should spend time threat modeling when they already use SAST and DAST tools in the pipeline. What is the best response?
Select an answer first - 7
A DevSecOps team is threat modeling a new application that processes sensitive customer data. They have identified several threats and are now deciding which mitigations to implement. The team has limited budget and time. What is the best way to decide which mitigations to implement?
Select an answer first - 8
A DevSecOps team is comparing STRIDE and PASTA for a new application. They need a methodology that will help them identify threats early in the design phase and also provide a structured way to prioritize them. Which methodology should they choose?
Select an answer first - 9
A DevSecOps team is integrating threat modeling into their CI/CD pipeline. They want to ensure that threat models are updated when code changes. Which approach is most effective?
Select an answer first - 10
Which of the following is a primary objective of threat modeling?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.