Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilIoT Security Essentials

Domain 5Objective 4

Threat Modeling Frameworks (STRIDE, DREAD, PASTA, CVSS) ISE Practice Questions (Page 4)

Part of the Cloud Security and Threat Intelligence domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
5concepts

Questions 16–20

  1. 16application · medium

    A security analyst is evaluating a vulnerability in an IoT device's firmware that allows remote code execution without authentication. The analyst needs to communicate the severity to management. Which approach best combines CVSS and DREAD to support the communication?

    Select an answer first
  2. 17application · medium

    An IoT security team identifies two threats to a fleet of medical wearables: Threat X requires physical access to each device and a rare exploit, but if successful it can alter patient dosage data. Threat Y can be triggered remotely by any unauthenticated user with a simple script, but it only causes a temporary loss of telemetry. Using DREAD, which threat should be prioritized as higher risk, and why?

    Select an answer first
  3. 18application · medium

    A medical IoT device transmits patient vitals to a cloud dashboard. A security analyst discovers that an attacker can replay captured messages to inject false readings, and that the device does not log who sent the data. The analyst wants to classify these issues using STRIDE and then assess their severity with CVSS. Which STRIDE categories apply, and which CVSS metric is most relevant to the lack of logging?

    Select an answer first
  4. 19foundation · easy

    A security analyst is calculating a CVSS v3.1 base score for a vulnerability in an IoT device. Which metric group is used to compute the base score?

    Select an answer first
  5. 20application · medium

    A smart-city project is deploying connected traffic lights. The team wants to use PASTA to model threats. In the first stage, they define business objectives such as minimizing traffic accidents and ensuring emergency vehicles get priority. In a later stage, they decompose the application to identify entry points and trust boundaries. Which PASTA stage comes immediately after application decomposition and before attack analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.