CCSP · Question #218
Which one of the following is not one of the three common threat modeling techniques?
The correct answer is D. Focused on social engineering. Common threat modeling techniques are typically focused on assets, attackers, or software, whereas social engineering is a type of attack, not a broad modeling approach.
Question
Which one of the following is not one of the three common threat modeling techniques?
Options
- AFocused on assets
- BFocused on attackers
- CFocused on software
- DFocused on social engineering
How the community answered
(68 responses)- A7% (5)
- B1% (1)
- C4% (3)
- D87% (59)
Why each option
Common threat modeling techniques are typically focused on assets, attackers, or software, whereas social engineering is a type of attack, not a broad modeling approach.
Focusing on assets is a common threat modeling technique that identifies valuable resources and potential threats to them.
Focusing on attackers is a common threat modeling technique that analyzes potential adversaries' capabilities, motivations, and attack vectors.
Focusing on software (or applications) is a common threat modeling technique that examines the application's design, code, and interactions to identify vulnerabilities.
Social engineering describes a type of attack that manipulates individuals into divulging confidential information or performing actions, but it is not considered one of the three foundational approaches or methodologies for conducting threat modeling itself.
Concept tested: Threat modeling techniques
Source: https://learn.microsoft.com/en-us/security/engineering/overview
Topics
Community Discussion
No community discussion yet for this question.