nerdexam
Cisco

300-220 · Question #122

What is the primary goal of using the STRIDE model in threat modeling?

The correct answer is B. Identify potential threats and their characteristics. B is correct because STRIDE is a structured framework used specifically to identify potential threats by categorizing them into six types: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege. Each letter represents a threat…

Threat Modeling Techniques

Question

What is the primary goal of using the STRIDE model in threat modeling?

Options

  • AIdentify potential attacker motivations and goals
  • BIdentify potential threats and their characteristics
  • CAssess the impact of security vulnerabilities
  • DEnsure the security of sensitive data

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    94% (29)
  • D
    3% (1)

Explanation

B is correct because STRIDE is a structured framework used specifically to identify potential threats by categorizing them into six types: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege. Each letter represents a threat category, and the model's primary purpose is to systematically surface what threats could exist against a system.

Why the distractors are wrong:

  • A is wrong - STRIDE focuses on threat categories, not attacker motivations or goals; that's more the domain of frameworks like ATT&CK.
  • C is wrong - assessing impact is part of risk assessment (e.g., DREAD model), which is a separate step that comes after threat identification.
  • D is wrong - protecting sensitive data is a security objective, not what STRIDE does; it's far too narrow to describe the full scope of the model.

Memory tip: Think of STRIDE as a checklist for what could go wrong, not how bad it is or why someone would do it. The six letters are your prompts to ask "could this system be spoofed? tampered with?" etc. - pure identification, no scoring.

Topics

#STRIDE model#Threat modeling#Threat identification#Threat enumeration

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice