Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilIoT Security Essentials

Domain 5Objective 4

Threat Modeling Frameworks (STRIDE, DREAD, PASTA, CVSS) ISE Practice Questions (Page 1)

Part of the Cloud Security and Threat Intelligence domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
5concepts

Questions 1–5

  1. 1foundation · easy

    During a threat modeling session for an IoT health-monitoring device, the team identifies that a compromised sensor could send false vital-sign readings to the cloud backend. Which STRIDE category best describes this threat?

    Select an answer first
  2. 2application · medium

    A security consultant is advising a manufacturing company on threat modeling for their new IoT-enabled assembly line. The company wants to identify threats, rate their risk, and then score the specific vulnerabilities found. Which combination of frameworks should the consultant recommend?

    Select an answer first
  3. 3application · medium

    A vulnerability in a smart meter's web interface has a CVSS base score of 9.8. The security team is deciding whether to patch immediately. They also perform a DREAD assessment and find that the vulnerability is easy to exploit and affects all customers. How should the team use these two scores to make a decision?

    Select an answer first
  4. 4foundation · easy

    A vulnerability in an IoT device has a CVSS v3.1 base score of 9.8. According to the CVSS severity ratings, how should this vulnerability be classified?

    Select an answer first
  5. 5expert · hard

    A smart-factory operator uses a mix of legacy and modern IoT devices. A threat model identifies that an attacker can spoof a sensor's identity to send false temperature readings, which could cause a production line to overheat. The team must decide whether to prioritize fixing the spoofing vulnerability or a separate vulnerability that allows remote code execution on a different device. The spoofing vulnerability has a CVSS score of 6.5, while the remote code execution has a CVSS score of 9.8. However, the spoofing vulnerability affects all 500 sensors, while the remote code execution affects only 10 devices. Using DREAD to prioritize, which vulnerability should be addressed first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.