Threat modeling is a process by which potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, can be identified and enumerated, and countermeasures prioritized.
- Source (Wiki)
Threat modeling is a proactive method of uncovering threats not usually considered or found through code reviews and other types of audits
- Techtarget
Taking my words back. From the OSG about the SAMM Model - Design The process used by the organization to define software requirements and create software. This function includes practices for threat modeling, threat assessment, security requirements, and security architecture. So, B is probably correct.
The correct answer is B. Threat modeling is a testing technique that enables the designer to develop mitigation strategies for potential vulnerabilities in software. It involves identifying potential threats and vulnerabilities in a software system and then developing and implementing strategies to mitigate those threats and vulnerabilities. This process can help to ensure that a software system is secure and can help to prevent security breaches and other types of cyber attacks. The other options listed are also testing techniques that can be used to identify potential vulnerabilities in software, but they do not directly enable the designer to develop mitigation strategies for those vulnerabilities.
It's A. Is source code review a testing technique? - Yes
Is it enables the designer to develop mitigation strategies for potential vulnerabilities? - Yes
Threat modeling is testing technique ? - No
Pentest allow to remidiate vulns that was fount and not potential.
Clearly answer is A.
threat modeling also implements test during the development phase
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.CISSP Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
dev46
Highly Voted 2 years, 1 month agojackdryan
1 year, 5 months agofranbarpro
Highly Voted 2 years agoTheManiac
Most Recent 5 months, 1 week agoVasyamba1
7 months, 1 week agoVasyamba1
7 months, 1 week agoVince_F_Fang
11 months, 3 weeks ago74gjd_37
1 year, 1 month agorootic
2 years agorootic
2 years agoRollizo
2 years ago