300-220 · Question #95
The PASTA method is used to:
The correct answer is A. Prioritize assets based on their criticality. PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling framework that guides security teams through identifying, analyzing, and prioritizing assets based on their business value and criticality - making A correct. It aligns business…
Question
The PASTA method is used to:
Options
- APrioritize assets based on their criticality
- BPrepare Italian dishes in the company cafeteria
- CPerform automated static analysis on software
- DConduct penetration testing on network infrastructure
How the community answered
(55 responses)- A91% (50)
- B2% (1)
- C5% (3)
- D2% (1)
Explanation
PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling framework that guides security teams through identifying, analyzing, and prioritizing assets based on their business value and criticality - making A correct. It aligns business objectives with technical risk, producing a prioritized view of threats and the assets most worth protecting.
B is a joke distractor playing on the word "pasta" - the culinary dish has no relation to security methodology. C is wrong because automated static analysis describes SAST (Static Application Security Testing) tools, a separate discipline. D is wrong because penetration testing follows its own frameworks (e.g., PTES, OSSTMM); PASTA is a threat modeling methodology, not a pentest execution guide.
Memory tip: Think of PASTA as the recipe for threat modeling - you identify your most valuable ingredients (assets), assess what could spoil them (threats), and prioritize accordingly. The acronym itself tells you what it does: Process for Attack Simulation and Threat Analysis.
Topics
Community Discussion
No community discussion yet for this question.