
EC-CouncilIoT Security Essentials
Domain 5Objective 4
Threat Modeling Frameworks (STRIDE, DREAD, PASTA, CVSS) ISE Practice Questions (Page 3)
Part of the Cloud Security and Threat Intelligence domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
5concepts
Questions 11–15
- 11
During a threat modeling exercise for a smart grid system, the team identifies a threat where an attacker can modify the firmware update process to install malicious code. They also note that the vulnerability has a high CVSS score. Which STRIDE category does this threat primarily represent, and how does the CVSS score help?
Select an answer first - 12
A security architect is selecting frameworks for a comprehensive IoT security program. The program needs to: identify threats during design, prioritize risks for remediation, and score specific vulnerabilities for compliance reporting. Which combination of frameworks would fulfill all three needs? Select all that apply.
Select an answer first - 13
A smart-transportation company is using PASTA to model threats to its fleet-management system. In the threat analysis stage, the team identifies a spoofing threat where an attacker can impersonate a vehicle's GPS unit. In the attack modeling stage, they simulate an attack that injects false GPS coordinates. In the vulnerability analysis stage, they find that the system does not authenticate GPS data. Which PASTA stage should the team perform next?
Select an answer first - 14
A vulnerability scanner reports a flaw in a smart thermostat's web interface. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The security team must decide whether to patch immediately or wait for the next maintenance window. Which interpretation of the CVSS score is most accurate?
Select an answer first - 15
A security analyst is reviewing a threat model for a smart-medication dispenser. The model identifies that an attacker can intercept and modify the prescription data sent from the doctor's portal to the dispenser, and that the dispenser does not verify the sender's identity. The analyst classifies the modification as Tampering and the lack of sender verification as Spoofing. How should the analyst interpret the CVSS metrics for a vulnerability that allows this attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.