nerdexam
(ISC)2

CCSP · Question #218

Which one of the following is not one of the three common threat modeling techniques?

The correct answer is D. Focused on social engineering. Common threat modeling techniques are typically focused on assets, attackers, or software, whereas social engineering is a type of attack, not a broad modeling approach.

Submitted by khalil_dz· Apr 18, 2026Cloud Application Security

Question

Which one of the following is not one of the three common threat modeling techniques?

Options

  • AFocused on assets
  • BFocused on attackers
  • CFocused on software
  • DFocused on social engineering

How the community answered

(68 responses)
  • A
    7% (5)
  • B
    1% (1)
  • C
    4% (3)
  • D
    87% (59)

Why each option

Common threat modeling techniques are typically focused on assets, attackers, or software, whereas social engineering is a type of attack, not a broad modeling approach.

AFocused on assets

Focusing on assets is a common threat modeling technique that identifies valuable resources and potential threats to them.

BFocused on attackers

Focusing on attackers is a common threat modeling technique that analyzes potential adversaries' capabilities, motivations, and attack vectors.

CFocused on software

Focusing on software (or applications) is a common threat modeling technique that examines the application's design, code, and interactions to identify vulnerabilities.

DFocused on social engineeringCorrect

Social engineering describes a type of attack that manipulates individuals into divulging confidential information or performing actions, but it is not considered one of the three foundational approaches or methodologies for conducting threat modeling itself.

Concept tested: Threat modeling techniques

Source: https://learn.microsoft.com/en-us/security/engineering/overview

Topics

#Threat modeling#Security analysis#Application security#Risk assessment

Community Discussion

No community discussion yet for this question.

Full CCSP Practice