
EC-CouncilIoT Security Essentials
Domain 5Objective 4
Threat Modeling Frameworks (STRIDE, DREAD, PASTA, CVSS) ISE Practice Questions (Page 5)
Part of the Cloud Security and Threat Intelligence domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
5concepts
Questions 21–25
- 21
A healthcare IoT device manufacturer is required by regulators to demonstrate that their threat modeling process considers business impact and includes attack simulation. However, the engineering team is already familiar with STRIDE and wants to continue using it. What is the best approach to satisfy both requirements?
Select an answer first - 22
A vulnerability in an IoT device has a CVSS base score of 9.0, but the DREAD assessment shows low Reproducibility and low Exploitability. The security team is debating whether to patch immediately. What is the most appropriate action?
Select an answer first - 23
A smart-agriculture company is evaluating two threats to its irrigation system. Threat A is a worm that spreads automatically across all 10,000 controllers, causing a 24-hour outage. Threat B is a targeted attack that requires physical access to a single controller and can permanently destroy that controller. The company has a limited budget and can only mitigate one threat. Using DREAD, which threat should be prioritized, and what is the primary reason?
Select an answer first - 24
A healthcare IoT vendor is required by a client to demonstrate that its threat modeling process is aligned with business objectives and includes attack simulation. The vendor currently uses STRIDE and DREAD. The client also wants a quantitative vulnerability severity score for each identified vulnerability. Which combination of frameworks should the vendor adopt to meet the client's requirements?
Select an answer first - 25
In the PASTA threat modeling methodology, which stage is specifically designed to simulate attacks against the identified threats to validate their exploitability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.