
EC-CouncilIoT Security Essentials
Domain 5Objective 3
Vulnerability Databases (National Vulnerability Database, US-CERT, Shodan) ISE Practice Questions (Page 10)
Part of the Cloud Security and Threat Intelligence domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
10concepts
Questions 46–48
- 46
An IoT security engineer is prioritizing patches for a fleet of smart meters. The engineer found a CVE entry in the NVD with a CVSS v3.1 base score of 9.8 and a vector string of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The engineer also noticed that the CPE entry for the affected firmware is listed as 'cpe:2.3:a:smart_meter_vendor:smart_meter_firmware:1.2.3:*:*:*:*:*:*:*'. Which interpretation of this data is most accurate for prioritization?
Select an answer first - 47
What is the main difference between a US-CERT Security Alert and a Security Advisory?
Select an answer first - 48
A vulnerability in the NVD has a CVSS base score of 9.8. How is this score typically interpreted?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ISE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ISE” is a trademark of its owner, used for identification only.