
EC-CouncilIoT Security Essentials
Domain 6Objective 3
The 12 Practices of the Microsoft Secure Development Lifecycle ISE Practice Questions (Page 5)
Part of the IoT Incident Response and Security Engineering domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 64 practice questions to prepare you well beyond it. (estimate)
64questions here
13free pages
13concepts
Questions 21–25
- 21
An IoT company is using a third-party real-time operating system (RTOS) in its new line of smart meters. The RTOS vendor has announced that it will no longer provide security patches after next year. The company must decide how to handle this risk while continuing to meet regulatory compliance. Which action is most aligned with SDL Practice 7?
Select an answer first - 22
A team developing a smart-lock product needs to encrypt communication between the lock and the mobile app. They are evaluating different encryption algorithms and key management approaches. The security lead insists that they use a well-established algorithm with a sufficient key length and that they avoid proprietary or homegrown crypto. Which SDL practice is the team following?
Select an answer first - 23
A team is preparing for the final security review of a smart-lock product. The security lead has compiled the threat models, security test results, and the list of known vulnerabilities. The product manager is pressuring the team to skip the review to meet a launch deadline. The security lead must decide how to proceed. Which action best aligns with the SDL's final security review practice?
Select an answer first - 24
A company has released a new firmware update for its smart thermostat product. The update includes a new third-party library for cloud connectivity. After the release, the operations team discovers that the library has a critical vulnerability. The team must decide how to respond. Which action best aligns with the SDL's release and operations security practice?
Select an answer first - 25
What is the main concern of the 'Manage the Security Risk of Third-Party Components' practice?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.