exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 313 discussion

Actual exam question from CompTIA's CS0-002
Question #: 313
Topic #: 1
[All CS0-002 Questions]

During the threat modeling process for a new application that a company is launching, a security analyst needs to define methods and items to take into consideration. Which of the following are part of a known threat modeling method?

  • A. Threat profile, infrastructure and application vulnerabilities, security strategy and plans
  • B. Purpose, objective, scope, team management, cost, roles and responsibilities
  • C. Spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege
  • D. Human impact, adversary's motivation, adversary's resources, adversary's methods
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gnnggnnggnng
Highly Voted 2 years, 2 months ago
Selected Answer: C
C. Spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege (STRIDE)
upvoted 10 times
...
novolyus
Most Recent 1 year, 4 months ago
Selected Answer: C
The STRIDE was initially created as part of the process of threat modeling. STRIDE is a model of threats, used to help reason and find threats to a system. It is used in conjunction with a model of the target system that can be constructed in parallel. This includes a full breakdown of processes, data stores, data flows, and trust boundaries.
upvoted 1 times
...
dickchappy
1 year, 5 months ago
Selected Answer: D
STRIDE is not mentioned in any official study materials or the objectives so I would never choose it as an option. D is describing the Diamond Model (Victim, Adversary, Infrastructure, Capability).
upvoted 1 times
...
skibby16
1 year, 6 months ago
Selected Answer: D
he other options (A, B, and C) include elements related to threat modeling, but they are not part of a known threat modeling method. Option A includes considerations like threat profile and security strategy, while Option B includes elements related to project management. Option C lists common security threats (spoofing, tampering, etc.) but doesn't address the overall threat modeling process.
upvoted 1 times
...
JoInn
2 years ago
Selected Answer: D
Even though I understand what you all mean when you say STRIDE, it's not in the objectives. What is instead, is Diamond model. That is D.
upvoted 3 times
...
2Fish
2 years, 1 month ago
Selected Answer: C
C, STRIDE. This excerpt taken from another member. Hello everyone, I'm going with A "STRIDE is a model of threats, used to help reason and find threats to a system." "Teams can use the STRIDE threat model to spot threats during the design phase of an app or system." "Threat modeling is becoming a more commonly used tool by software development teams as they integrate security into their development lifecycle. " -Blehbleh
upvoted 1 times
...
opem
2 years, 1 month ago
Selected Answer: C
https://www.examtopics.com/discussions/comptia/view/69694-exam-cs0-002-topic-1-question-278-discussion/
upvoted 3 times
...
CatoFong
2 years, 2 months ago
Selected Answer: C
Stride for the win. gnng x3 didn't even need ai for that one
upvoted 3 times
gnnggnnggnng
2 years, 2 months ago
I wish You had enough time to put some explanations along....Help is always appreciated by community (some part of it).
upvoted 3 times
CatoFong
2 years, 2 months ago
Me too. But you're supplying very detailed answers which is appreciated.
upvoted 3 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago