Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilIoT Security Essentials

Domain 6Objective 4

Threat Modeling ISE Practice Questions (Page 5)

Part of the IoT Incident Response and Security Engineering domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
9concepts

Questions 21–25

  1. 21application · medium · select all that apply

    A smart factory is threat modeling its industrial IoT environment. The team is identifying assets to include in the threat model. Which of the following should be classified as assets in the threat model? Select all that apply.

    Select an answer first
  2. 22foundation · easy

    Which attack vector is particularly relevant to IoT ecosystems due to the use of wireless communication?

    Select an answer first
  3. 23application · medium

    A medical-device manufacturer is threat modeling a wearable glucose monitor that transmits patient data via Bluetooth Low Energy (BLE) to a smartphone app, which then uploads to a cloud portal. The team is identifying assets and entry points. Which item should be classified as an entry point rather than an asset?

    Select an answer first
  4. 24expert · hard

    An IoT security team has identified several threats to a smart factory. They have limited budget and must decide which threats to mitigate first. Threat 1: a vulnerability in the firmware update process that could allow remote code execution on all robots (likelihood 3, impact 5). Threat 2: a denial-of-service attack on the local network that could halt production (likelihood 4, impact 4). Threat 3: a data breach of customer order information stored in the cloud (likelihood 2, impact 5). Threat 4: physical tampering with sensors that could cause incorrect readings (likelihood 5, impact 2). Using a risk matrix that prioritizes high-impact threats even if likelihood is moderate, which threat should be addressed first?

    Select an answer first
  5. 25expert · hard

    A logistics company uses IoT trackers on shipping containers. The threat model identified two threats: Threat A: an attacker can spoof a tracker's location data, causing misrouting (likelihood: medium, impact: high). Threat B: an attacker can drain the tracker's battery by sending excessive wake-up signals (likelihood: high, impact: low). The company has a limited security budget. Which threat should be prioritized, and why?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.