
Certified Information Systems Security Professional
Domain 1Objective 10
1.10 - Understand and Apply Threat Modeling Concepts and Methodologies CISSP Practice Questions (Page 2)
Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
4concepts
16%of the exam
Questions 6–10
- 6
In the STRIDE threat modeling methodology, which threat type corresponds to an attacker gaining unauthorized access to data?
Select an answer first - 7
What is the first step in a typical threat modeling process?
Select an answer first - 8
A web application allows users to upload profile pictures. Which threat is most directly relevant to this feature?
Select an answer first - 9
A healthcare organization is deploying a new patient portal that allows patients to view their medical records online. The security team is using STRIDE to analyze threats. They identify that an attacker could intercept the patient's session token and impersonate the patient. Which STRIDE category does this threat fall under?
Select an answer first - 10
A security analyst is using STRIDE to analyze a new file-sharing application. The team identifies that a user could deny having uploaded a malicious file, and there is no audit trail to prove otherwise. Which STRIDE category does this threat represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.