nerdexam
(ISC)2

CCSP · Question #298

Which of the following is not a component of the of the STRIDE model? Response:

The correct answer is D. External pen testing. External pen testing is a security evaluation method, not a threat category within the STRIDE model, which classifies threats by Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

Submitted by rania.sa· Apr 18, 2026Cloud Application Security

Question

Which of the following is not a component of the of the STRIDE model? Response:

Options

  • ASpoofing
  • BRepudiation
  • CInformation disclosure
  • DExternal pen testing

How the community answered

(41 responses)
  • A
    5% (2)
  • B
    2% (1)
  • C
    2% (1)
  • D
    90% (37)

Why each option

External pen testing is a security evaluation method, not a threat category within the STRIDE model, which classifies threats by Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

ASpoofing

Spoofing is a recognized threat category in the STRIDE model, referring to impersonating something or someone.

BRepudiation

Repudiation is a recognized threat category in the STRIDE model, referring to the ability of an attacker to deny having performed an action.

CInformation disclosure

Information disclosure is a recognized threat category in the STRIDE model, referring to the exposure of sensitive data to unauthorized individuals.

DExternal pen testingCorrect

External pen testing (penetration testing) is a method for evaluating security by simulating attacks, not a threat category within the STRIDE model, which classifies threats as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

Concept tested: STRIDE threat model components

Source: https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-stride

Topics

#STRIDE model#Threat modeling#Application security#Security threats

Community Discussion

No community discussion yet for this question.

Full CCSP Practice