
Certified Information Systems Security Professional
Domain 1Objective 10
1.10 - Understand and Apply Threat Modeling Concepts and Methodologies CISSP Practice Questions (Page 5)
Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
4concepts
16%of the exam
Questions 21–23
- 21
A security team is comparing threat modeling methodologies. They need a methodology that is particularly effective for analyzing a single, high-value target, such as a critical database server, by breaking down the various ways an attacker could compromise it. Which methodology is best suited for this?
Select an answer first - 22
A security team is threat modeling a new IoT device that collects health data from patients and transmits it to a cloud backend. The team has limited time and budget. They need to identify the most critical threats quickly and focus mitigation efforts on the highest-risk areas. Which approach is most efficient?
Select an answer first - 23
A security team is threat modeling a new customer-facing web application. They have identified that the application stores sensitive customer data and is accessible over the internet. They have enumerated several threats, including SQL injection, cross-site scripting (XSS), and session hijacking. The team has limited budget and must prioritize which threats to mitigate first. Which threat should be given the highest priority?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISSP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.