
EC-CouncilIoT Security Essentials
Domain 5Objective 4
Threat Modeling Frameworks (STRIDE, DREAD, PASTA, CVSS) ISE Practice Questions (Page 8)
Part of the Cloud Security and Threat Intelligence domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
5concepts
Questions 36–40
- 36
A security team is using the DREAD model to prioritize threats to an IoT fleet-management system. They are evaluating a threat where an attacker can remotely disable vehicle tracking. Which DREAD component measures the potential financial and operational impact if the threat is realized?
Select an answer first - 37
A threat analyst is applying the DREAD model to rate a vulnerability in an IoT device's firmware update process. They assign a score of 10 for the 'Discoverability' component. What does this high score indicate?
Select an answer first - 38
A smart-energy company is required by a regulator to perform threat modeling that includes a business impact analysis and attack simulation. The company also needs to compare the severity of known vulnerabilities across its vendor products using a standardized, industry-recognized scale. The security team is considering using PASTA, DREAD, and CVSS. Which combination of frameworks should they use, and why?
Select an answer first - 39
A security analyst is using STRIDE to identify threats for a smart home system. They identify a threat where an attacker can gain administrative access to the hub by exploiting a buffer overflow. Which STRIDE category does this threat primarily fall under, and how would DREAD help in this context?
Select an answer first - 40
A smart-home device manufacturer wants to adopt a threat modeling approach that is comprehensive, aligns with business objectives, and includes attack simulation. The company also wants to ensure that all threat categories are considered during design reviews. Which combination of frameworks should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.