CAS-005 · Question #409
A company wants to perform threat modeling on an internally developed, business-critical application. The Chief Information Security Officer (CISO) is most concerned that the application should…
The correct answer is B. STRIDE. STRIDE is a threat-modeling framework that focuses on six key threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. This directly addresses the CISO’s concerns about ensuring high availability (99.999%) and…
Question
A company wants to perform threat modeling on an internally developed, business-critical application. The Chief Information Security Officer (CISO) is most concerned that the application should maintain 99.999% availability and authorized users should only be able to gain access to data they are explicitly authorized to view. Which of the following threat-modeling frameworks directly addresses the CISO’s concerns about this system?
Options
- ACAPEC
- BSTRIDE
- CATT&CK
- DTAXII
How the community answered
(38 responses)- A3% (1)
- B95% (36)
- D3% (1)
Explanation
STRIDE is a threat-modeling framework that focuses on six key threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. This directly addresses the CISO’s concerns about ensuring high availability (99.999%) and restricting data access to only authorized users, making it the most suitable choice.
Community Discussion
No community discussion yet for this question.