Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 2Objective 1

Threat Modeling Concepts ECDE Practice Questions (Page 6)

Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.

35questions here
7free pages
5concepts

Questions 26–30

  1. 26foundation · easy

    Which of the following represents the correct order of steps in a typical threat modeling process?

    Select an answer first
  2. 27foundation · easy

    What is a key goal of threat modeling in the context of software development?

    Select an answer first
  3. 28application · medium

    A company wants to embed threat modeling into its DevSecOps pipeline so that security analysis happens continuously as code changes. The team is concerned about slowing down developers. Which approach best balances early and continuous security analysis with developer velocity?

    Select an answer first
  4. 29expert · hard

    A DevSecOps team is threat modeling a new feature that allows users to upload files. They have created a data flow diagram and identified that the file storage service is a trust boundary. They are now at the step of identifying threats. Which approach is most aligned with the threat modeling process?

    Select an answer first
  5. 30application · medium

    A DevSecOps team is threat modeling a new API gateway. They have created a data flow diagram and identified trust boundaries. What should they do next in the threat modeling process?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.