nerdexam
(ISC)2

CISSP · Question #1448

What is the BEST method to use for assessing the security impact of acquired software?

The correct answer is C. Threat modeling. The best method to use for assessing the security impact of acquired software is threat modeling. Threat modeling is a method that involves identifying, analyzing, and prioritizing the possible threats and attacks that can affect the security of the software, and the correspondin

Submitted by ricky.ec· Mar 5, 2026Software Development Security

Question

What is the BEST method to use for assessing the security impact of acquired software?

Options

  • ACommon vulnerability review
  • BSoftware security compliance validation
  • CThreat modeling
  • DVendor assessment

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    75% (24)
  • D
    13% (4)

Explanation

The best method to use for assessing the security impact of acquired software is threat modeling. Threat modeling is a method that involves identifying, analyzing, and prioritizing the possible threats and attacks that can affect the security of the software, and the corresponding countermeasures and mitigations that can prevent or reduce the impact of the threats and attacks. Threat modeling can help to assess the security impact of acquired software, as it can help to evaluate and validate the security assumptions and requirements, and to identify and address the security gaps and weaknesses of the software. Threat modeling can also help to assess the security impact of acquired software, as it can help to estimate and quantify the potential damage or loss caused by the threats and attacks, and to align the security controls with the risk appetite and tolerance of the organization.

Topics

#Software acquisition security#Threat modeling#Supply chain security#Risk assessment

Community Discussion

No community discussion yet for this question.

Full CISSP Practice