Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 1Objective 10

1.10 - Understand and Apply Threat Modeling Concepts and Methodologies CISSP Practice Questions (Page 1)

Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
4concepts
16%of the exam

Questions 1–5

  1. 1application · medium

    A software development team is conducting a threat modeling exercise for a new customer relationship management (CRM) application. They have identified the data assets, created data flow diagrams, and enumerated potential threats. According to a typical threat modeling process, what should the team do next?

    Select an answer first
  2. 2foundation · easy

    Which statement best describes the role of threat modeling in the software development lifecycle?

    Select an answer first
  3. 3foundation · easy

    Which threat modeling methodology is specifically designed to analyze threats from an attacker's perspective by focusing on the attacker's goals?

    Select an answer first
  4. 4application · medium

    A team is threat modeling a new online ordering system. They have created a data flow diagram showing that customer order data flows from the web server to the database. They are now identifying threats. Which step of the threat modeling process are they performing?

    Select an answer first
  5. 5expert · medium

    A threat modeling team is working on a new payment application. They have identified that the application processes credit card data, and they have created a data flow diagram. During threat enumeration, they identify a threat where an attacker could intercept the credit card data in transit. The team is now deciding on mitigations. Which mitigation is most appropriate for this threat?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.