300-220 · Question #54
In the context of PASTA, what is the main focus during threat modeling?
The correct answer is B. Application and system vulnerabilities. PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling framework that centers on identifying application and system vulnerabilities (B) to simulate real-world attacks and understand their business impact - making B correct. The entire PASTA…
Question
In the context of PASTA, what is the main focus during threat modeling?
Options
- APasta recipes for team building
- BApplication and system vulnerabilities
- CLegal ramifications of data breaches
- DPhysical security measures
How the community answered
(37 responses)- A3% (1)
- B86% (32)
- C8% (3)
- D3% (1)
Explanation
PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling framework that centers on identifying application and system vulnerabilities (B) to simulate real-world attacks and understand their business impact - making B correct. The entire PASTA methodology is structured around seven stages that progressively analyze software architecture, enumerate threats, and enumerate vulnerabilities to help organizations prioritize security risks.
Why the distractors are wrong:
- A is a nonsense distractor - PASTA is a security acronym, not culinary.
- C (legal ramifications) may be a downstream concern after a breach, but it is not PASTA's focus; PASTA is proactive, not reactive/legal.
- D (physical security) falls under a different domain (e.g., PACS or general security management) - PASTA is specifically for software/application threat modeling.
Memory tip: Think of PASTA as "Pick Apart Software Threats & Attacks" - its entire purpose is dissecting application vulnerabilities to simulate what an attacker could exploit, keeping your focus squarely on software and system weaknesses.
Topics
Community Discussion
No community discussion yet for this question.