
EC-CouncilIoT Security Essentials
Domain 5Objective 4
Threat Modeling Frameworks (STRIDE, DREAD, PASTA, CVSS) ISE Practice Questions (Page 7)
Part of the Cloud Security and Threat Intelligence domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
5concepts
Questions 31–35
- 31
A security analyst is comparing two vulnerabilities in a smart-building system. Vulnerability 1 has a CVSS base score of 9.0, but it only affects 5 devices in a single building. Vulnerability 2 has a CVSS base score of 5.0, but it affects 1,000 devices across multiple buildings. The analyst must decide which vulnerability to remediate first. The organization uses DREAD for prioritization. Which vulnerability should be prioritized, and why?
Select an answer first - 32
A smart-building operator needs to identify all possible threat types in its access-control system and then prioritize them for remediation. The team wants a structured way to ensure no threat category is overlooked, followed by a simple numeric prioritization. Which combination of frameworks best achieves this?
Select an answer first - 33
A smart-home vendor has a limited budget and must fix one of two vulnerabilities. Vulnerability A can be exploited remotely by any unauthenticated user with a known public exploit, and it affects all 100,000 deployed devices, but the impact is limited to a temporary loss of voice-assistant functionality. Vulnerability B requires physical access to a device and a custom exploit, and it affects only 100 devices, but it can permanently brick the device. Using DREAD, which vulnerability should the vendor prioritize?
Select an answer first - 34
A security team needs to choose a threat modeling approach for an IoT system where the primary goal is to prioritize vulnerabilities based on a standardized, industry-recognized severity score that can be compared across different products. Which framework is most appropriate?
Select an answer first - 35
A smart-lock vendor receives a report that a firmware update can be intercepted and replaced during transmission, allowing an attacker to install malicious code. The vendor wants to classify this threat using STRIDE and then quantify its severity with CVSS. Which STRIDE category best fits the threat, and which CVSS metric is most directly affected by the attacker's ability to replace the update?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.