nerdexam
EC-Council

312-85 · Question #2

Lizzy, an analyst, wants to recognize the level of risks to the organization so as to plan countermeasures against cyber attacks. She used a threat modelling methodology where she performed the…

The correct answer is C. OCTAVE. OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation), developed by Carnegie Mellon's CERT, is correct because its three-phase structure maps exactly to the scenario: Phase 1 builds asset-based threat profiles, Phase 2 identifies infrastructure…

Threat Intelligence Analysis

Question

Lizzy, an analyst, wants to recognize the level of risks to the organization so as to plan countermeasures against cyber attacks. She used a threat modelling methodology where she performed the following stages:

Stage 1: Build asset-based threat profiles Stage 2: Identify infrastructure vulnerabilities Stage 3: Develop security strategy and plans Which of the following threat modelling methodologies was used by Lizzy in the aforementioned scenario?

Options

  • ATRIKE
  • BVAST
  • COCTAVE
  • DDREAD

How the community answered

(25 responses)
  • B
    4% (1)
  • C
    92% (23)
  • D
    4% (1)

Explanation

OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation), developed by Carnegie Mellon's CERT, is correct because its three-phase structure maps exactly to the scenario: Phase 1 builds asset-based threat profiles, Phase 2 identifies infrastructure vulnerabilities, and Phase 3 develops the security strategy and plans. TRIKE is wrong because it uses a requirements model and risk-based approach centered on acceptable risk, not a three-stage asset-first workflow. VAST (Visual, Agile, and Simple Threat modeling) is wrong because it targets Agile/DevOps pipelines at enterprise scale and produces application and operational threat models, not this specific sequence. DREAD is wrong because it is not a full methodology at all - it is a scoring system used to rate threats by Damage, Reproducibility, Exploitability, Affected users, and Discoverability.

Memory tip: Remember OCTAVE by its order of operations - Assets → Infrastructure → Strategy (A-I-S). If a methodology starts with assets before touching technology, think OCTAVE.

Topics

#OCTAVE methodology#threat modeling#risk assessment#asset-based approach

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice