nerdexam
Microsoft

SC-100 · Question #149

You are a security architect, and you are working with your software development team and defining a strategy for an application lifecycle management process, This process is based on the Microsoft…

The correct answer is B. Diagram C. Identify. Option A is incorrect because planning is not part of the threat model design. Option B is correct because the second phase of threat modeling is defining a visual representation of critical data flows and interactions. This piece is called a diagram. Option C is correct…

Design security solutions for applications and data

Question

You are a security architect, and you are working with your software development team and defining a strategy for an application lifecycle management process, This process is based on the Microsoft Security Development Lifecycle Model. What are the two phases in the threat modeling design phase?

Options

  • APlanning
  • BDiagram
  • CIdentify
  • DReview

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    90% (26)
  • D
    7% (2)

Explanation

Option A is incorrect because planning is not part of the threat model design. Option B is correct because the second phase of threat modeling is defining a visual representation of critical data flows and interactions. This piece is called a diagram. Option C is correct because in the identify stage you identify and prioritize for mitigation specific to the product security requirements. Option D is incorrect because Review is not part of the threat model design https://learn.microsoft.com/en-us/compliance/assurance/assurance-microsoft-security- developmnt-lifecycle

Topics

#Microsoft SDL#Threat Modeling#Application Security Lifecycle#Security Architecture

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice