312-85 · Question #2
Lizzy, an analyst, wants to recognize the level of risks to the organization so as to plan countermeasures against cyber attacks. She used a threat modelling methodology where she performed the…
The correct answer is C. OCTAVE. OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation), developed by Carnegie Mellon's CERT, is correct because its three-phase structure maps exactly to the scenario: Phase 1 builds asset-based threat profiles, Phase 2 identifies infrastructure…
Question
Lizzy, an analyst, wants to recognize the level of risks to the organization so as to plan countermeasures against cyber attacks. She used a threat modelling methodology where she performed the following stages:
Stage 1: Build asset-based threat profiles Stage 2: Identify infrastructure vulnerabilities Stage 3: Develop security strategy and plans Which of the following threat modelling methodologies was used by Lizzy in the aforementioned scenario?
Options
- ATRIKE
- BVAST
- COCTAVE
- DDREAD
How the community answered
(25 responses)- B4% (1)
- C92% (23)
- D4% (1)
Explanation
OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation), developed by Carnegie Mellon's CERT, is correct because its three-phase structure maps exactly to the scenario: Phase 1 builds asset-based threat profiles, Phase 2 identifies infrastructure vulnerabilities, and Phase 3 develops the security strategy and plans. TRIKE is wrong because it uses a requirements model and risk-based approach centered on acceptable risk, not a three-stage asset-first workflow. VAST (Visual, Agile, and Simple Threat modeling) is wrong because it targets Agile/DevOps pipelines at enterprise scale and produces application and operational threat models, not this specific sequence. DREAD is wrong because it is not a full methodology at all - it is a scoring system used to rate threats by Damage, Reproducibility, Exploitability, Affected users, and Discoverability.
Memory tip: Remember OCTAVE by its order of operations - Assets → Infrastructure → Strategy (A-I-S). If a methodology starts with assets before touching technology, think OCTAVE.
Topics
Community Discussion
No community discussion yet for this question.