nerdexam
(ISC)2

CCSP · Question #75

What are the six components that make up the STRIDE threat model?

The correct answer is A. Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of. The STRIDE threat model categorizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

Submitted by asante_acc· Apr 18, 2026Cloud Concepts, Architecture and Design

Question

What are the six components that make up the STRIDE threat model?

Options

  • ASpoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of
  • BSpoofing, Tampering, Non-Repudiation, Information Disclosure, Denial of Service, and Elevation
  • CSpoofing, Tampering, Repudiation, Information Disclosure, Distributed Denial of Service, and
  • DSpoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Social

How the community answered

(16 responses)
  • A
    94% (15)
  • C
    6% (1)

Why each option

The STRIDE threat model categorizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

ASpoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation ofCorrect

The six components that make up the STRIDE threat model are Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

BSpoofing, Tampering, Non-Repudiation, Information Disclosure, Denial of Service, and Elevation

'Non-Repudiation' is a security property, not a type of threat within STRIDE; 'Repudiation' is the correct threat component.

CSpoofing, Tampering, Repudiation, Information Disclosure, Distributed Denial of Service, and

'Distributed Denial of Service' is a specific type of Denial of Service attack, but the STRIDE model uses the broader 'Denial of Service.'

DSpoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Social

'Social Engineering' is a category of attack vector, not one of the six core threat types defined by STRIDE.

Concept tested: STRIDE threat model components

Source: https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-stride

Topics

#STRIDE Threat Model#Threat Modeling#Security Assessment

Community Discussion

No community discussion yet for this question.

Full CCSP Practice