During the threat modeling process for a new application that a company is launching, a security analyst needs to define methods and items to take into consideration. Which of the following are part of a known threat modeling method?
A.
Threat profile, infrastructure and application vulnerabilities, security strategy and plans
B.
Purpose, objective, scope, team management, cost, roles and responsibilities
C.
Spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege
D.
Human impact, adversary's motivation, adversary's resources, adversary's methods
The STRIDE was initially created as part of the process of threat modeling. STRIDE is a model of threats, used to help reason and find threats to a system. It is used in conjunction with a model of the target system that can be constructed in parallel. This includes a full breakdown of processes, data stores, data flows, and trust boundaries.
STRIDE is not mentioned in any official study materials or the objectives so I would never choose it as an option. D is describing the Diamond Model (Victim, Adversary, Infrastructure, Capability).
he other options (A, B, and C) include elements related to threat modeling, but they are not part of a known threat modeling method. Option A includes considerations like threat profile and security strategy, while Option B includes elements related to project management. Option C lists common security threats (spoofing, tampering, etc.) but doesn't address the overall threat modeling process.
C, STRIDE. This excerpt taken from another member.
Hello everyone, I'm going with A "STRIDE is a model of threats, used to help reason and find threats to a system." "Teams can use the STRIDE threat model to spot threats during the design phase of an app or system." "Threat modeling is becoming a more commonly used tool by software development teams as they integrate security into their development lifecycle. " -Blehbleh
Me too. But you're supplying very detailed answers which is appreciated.
upvoted 3 times
...
...
...
This section is not available anymore. Please use the main Exam Page.CS0-002 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
gnnggnnggnng
Highly Voted 2 years, 2 months agonovolyus
Most Recent 1 year, 4 months agodickchappy
1 year, 5 months agoskibby16
1 year, 6 months agoJoInn
2 years ago2Fish
2 years, 1 month agoopem
2 years, 1 month agoCatoFong
2 years, 2 months agognnggnnggnng
2 years, 2 months agoCatoFong
2 years, 2 months ago