Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilIoT Security Essentials

Domain 5Objective 4

Threat Modeling Frameworks (STRIDE, DREAD, PASTA, CVSS) ISE Practice Questions (Page 6)

Part of the Cloud Security and Threat Intelligence domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
5concepts

Questions 26–30

  1. 26expert · hard

    A security team is prioritizing vulnerabilities for a fleet of IoT devices. They have CVSS scores for each vulnerability, but management wants a more business-focused prioritization. The team decides to use DREAD, but they are concerned about the subjectivity of DREAD scores. What is the best way to address this concern while still using DREAD?

    Select an answer first
  2. 27application · medium

    A smart-city project is deploying connected traffic lights. The security team needs to ensure that threat modeling aligns with the city's business objective of maintaining traffic flow and public safety. They want to simulate realistic attack scenarios against the traffic light control system and involve business stakeholders in the process. Which threat modeling methodology best fits this requirement?

    Select an answer first
  3. 28application · medium

    A wearable-device manufacturer wants to adopt a threat modeling approach that is lightweight, does not require extensive business analysis, and helps the team quickly categorize threats during design reviews. They also want to ensure they cover all major threat types. Which framework is the best fit?

    Select an answer first
  4. 29expert · hard

    A security analyst is comparing two vulnerabilities in IoT devices. Vulnerability A has a CVSS base score of 7.5, and Vulnerability B has a CVSS base score of 6.5. However, the DREAD assessment shows that Vulnerability B has higher Damage and Affected Users scores. How should the analyst prioritize these vulnerabilities?

    Select an answer first
  5. 30expert · hard

    A large enterprise is deploying IoT devices across multiple regions. They need to choose a threat modeling approach that can scale across teams and align with global business objectives. They also need to produce consistent, repeatable results. Which approach is most suitable?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.