Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilIoT Security Essentials

Domain 6Objective 4

Threat Modeling ISE Practice Questions (Page 7)

Part of the IoT Incident Response and Security Engineering domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
9concepts

Questions 31–35

  1. 31application · medium

    A smart warehouse company completed a threat model for its inventory tracking system. The team identified a medium-risk threat involving unauthorized access to the inventory database. The project manager wants to communicate the threat model to the warehouse operations team, who are not security experts. What is the most effective way to present the threat?

    Select an answer first
  2. 32expert · hard

    A threat modeling team has completed a detailed analysis of a smart building system and produced a lengthy technical report. The facility manager, who is not technical, needs to understand the top risks and approve a budget for mitigations. The team also needs to ensure that developers can act on the findings. What is the most effective way to communicate the threat model to both audiences?

    Select an answer first
  3. 33application · medium

    A smart building company uses DREAD to score threats to its IoT access-control system. Threat A: an attacker can remotely unlock doors by exploiting a firmware vulnerability (scores: Damage 9, Reproducibility 8, Exploitability 7, Affected Users 8, Discoverability 5). Threat B: an attacker can cause a temporary denial of service by flooding the management interface (scores: Damage 4, Reproducibility 9, Exploitability 9, Affected Users 6, Discoverability 8). Which threat should be prioritized for mitigation, and why?

    Select an answer first
  4. 34application · medium

    A smart-building vendor is threat modeling a new IoT access-control system. The system includes edge controllers that manage door locks, a cloud backend for credential management, and a mobile app for administrators. The team wants to systematically identify threats by examining each component's interactions and data flows, focusing on spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. Which approach should the team use?

    Select an answer first
  5. 35expert · hard

    A security engineer is threat modeling a smart home system with a central hub, multiple sensors, and a cloud service. The team has identified a threat where an attacker could send malicious commands to the hub via the internet. They need to decide on a mitigation. The team is considering using STRIDE to categorize the threat and then develop a mitigation. Which mitigation is most appropriate for the threat of unauthorized command injection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.