Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Information Systems Security Professional

Domain 1Objective 10

1.10 - Understand and Apply Threat Modeling Concepts and Methodologies CISSP Practice Questions (Page 3)

Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
4concepts
16%of the exam

Questions 11–15

  1. 11application · medium

    A company is developing a new employee self-service portal. The security team is conducting a threat modeling exercise. They have identified the portal's assets, including employee PII, and have created a data flow diagram. They are now brainstorming potential threats, such as an attacker exploiting a SQL injection vulnerability to access the database. Which step of the threat modeling process are they performing?

    Select an answer first
  2. 12application · medium

    A threat modeling team has completed the following activities: identified critical assets, created data flow diagrams, and enumerated threats. They now need to decide which threats to address first. Which activity should they perform next?

    Select an answer first
  3. 13application · medium

    A threat modeling team is working on a new online payment system. They have identified the assets (e.g., payment data), created a data flow diagram, and enumerated threats. They are now evaluating the likelihood and impact of each threat to determine which ones require immediate attention. Which step of the threat modeling process are they performing?

    Select an answer first
  4. 14application · medium

    A security analyst is using an attack tree to model threats to a company's remote access VPN. The root goal is 'Gain unauthorized access to the corporate network.' Which of the following would be an appropriate child node under this root goal?

    Select an answer first
  5. 15application · medium

    A threat modeling team has identified that a new online banking application has a high-risk threat of session hijacking. The team decides to implement multi-factor authentication and session timeouts to mitigate this threat. Which step of the threat modeling process does this represent?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.