nerdexam
CompTIA

CAS-005 · Question #409

A company wants to perform threat modeling on an internally developed, business-critical application. The Chief Information Security Officer (CISO) is most concerned that the application should…

The correct answer is B. STRIDE. STRIDE is a threat-modeling framework that focuses on six key threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. This directly addresses the CISO’s concerns about ensuring high availability (99.999%) and…

Submitted by hans_de· Mar 6, 2026Security Architecture

Question

A company wants to perform threat modeling on an internally developed, business-critical application. The Chief Information Security Officer (CISO) is most concerned that the application should maintain 99.999% availability and authorized users should only be able to gain access to data they are explicitly authorized to view. Which of the following threat-modeling frameworks directly addresses the CISO’s concerns about this system?

Options

  • ACAPEC
  • BSTRIDE
  • CATT&CK
  • DTAXII

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    95% (36)
  • D
    3% (1)

Explanation

STRIDE is a threat-modeling framework that focuses on six key threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. This directly addresses the CISO’s concerns about ensuring high availability (99.999%) and restricting data access to only authorized users, making it the most suitable choice.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice