nerdexam
Cisco

300-220 · Question #54

In the context of PASTA, what is the main focus during threat modeling?

The correct answer is B. Application and system vulnerabilities. PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling framework that centers on identifying application and system vulnerabilities (B) to simulate real-world attacks and understand their business impact - making B correct. The entire PASTA…

Threat Modeling Techniques

Question

In the context of PASTA, what is the main focus during threat modeling?

Options

  • APasta recipes for team building
  • BApplication and system vulnerabilities
  • CLegal ramifications of data breaches
  • DPhysical security measures

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    86% (32)
  • C
    8% (3)
  • D
    3% (1)

Explanation

PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling framework that centers on identifying application and system vulnerabilities (B) to simulate real-world attacks and understand their business impact - making B correct. The entire PASTA methodology is structured around seven stages that progressively analyze software architecture, enumerate threats, and enumerate vulnerabilities to help organizations prioritize security risks.

Why the distractors are wrong:

  • A is a nonsense distractor - PASTA is a security acronym, not culinary.
  • C (legal ramifications) may be a downstream concern after a breach, but it is not PASTA's focus; PASTA is proactive, not reactive/legal.
  • D (physical security) falls under a different domain (e.g., PACS or general security management) - PASTA is specifically for software/application threat modeling.

Memory tip: Think of PASTA as "Pick Apart Software Threats & Attacks" - its entire purpose is dissecting application vulnerabilities to simulate what an attacker could exploit, keeping your focus squarely on software and system weaknesses.

Topics

#PASTA threat modeling#Vulnerability analysis#Threat modeling methodology#Application security

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice