nerdexam
(ISC)2

CISSP · Question #625

Which of the following practices provides the development team with a definition of security and identification of threats in designing software?

The correct answer is C. Threat modeling. Threat modeling is a practice that provides the development team with a definition of security and identification of threats in designing software. Threat modeling is a process of analyzing the software system or application from the perspective of an attacker, and identifying…

Submitted by alyssa_d· Mar 5, 2026Software Development Security

Question

Which of the following practices provides the development team with a definition of security and identification of threats in designing software?

Options

  • APenetration testing
  • BStakeholder review
  • CThreat modeling
  • DRequirements review

How the community answered

(22 responses)
  • B
    5% (1)
  • C
    95% (21)

Explanation

Threat modeling is a practice that provides the development team with a definition of security and identification of threats in designing software. Threat modeling is a process of analyzing the software system or application from the perspective of an attacker, and identifying the potential threats, vulnerabilities, and risks that may affect the security of the software system or application. Threat modeling can help to improve the security awareness and mindset of the development team, as well as to guide the security design and implementation decisions of the software system or application. Penetration testing, stakeholder review, or requirements review are not the best practices to provide the development team with a definition of security and identification of threats in designing software, as they are more related to the testing, evaluation, or specification aspects of software development.

Topics

#Threat modeling#Software design security#SDLC security

Community Discussion

No community discussion yet for this question.

Full CISSP Practice