Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilIoT Security Essentials

Domain 5Objective 4

Threat Modeling Frameworks (STRIDE, DREAD, PASTA, CVSS) ISE Practice Questions (Page 2)

Part of the Cloud Security and Threat Intelligence domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
5concepts

Questions 6–10

  1. 6foundation · easy

    A security architect is adopting the PASTA threat modeling methodology for an IoT payment system. Which stage of PASTA involves defining the business objectives and security requirements that the threat model must support?

    Select an answer first
  2. 7application · medium

    A smart-agriculture company wants to prioritize security investments for its irrigation control system. The business objective is to prevent crop loss from ransomware attacks that could lock out control systems during the growing season. The team needs a threat modeling approach that explicitly ties technical threats to business impact and includes attack simulation. Which framework best fits this need?

    Select an answer first
  3. 8foundation · easy

    An IoT security analyst wants to identify and categorize threats in a smart home system, focusing on the types of threats such as spoofing, tampering, and denial of service. Which framework is specifically designed for this categorization?

    Select an answer first
  4. 9application · medium

    A security analyst is comparing two vulnerabilities in an IoT gateway. Vulnerability 1 has a CVSS base score of 9.8, and Vulnerability 2 has a CVSS base score of 4.2. The analyst also performs a DREAD assessment and finds that Vulnerability 2 has a higher DREAD score than Vulnerability 1. What is the most likely explanation for this discrepancy?

    Select an answer first
  5. 10expert · hard

    A security team is using PASTA to model threats for a new IoT product. They have completed the business impact analysis and are now in the attack simulation stage. They need to prioritize the simulated attack scenarios. Which framework should they use to rate and prioritize these scenarios?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.