CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium

A security analyst is conducting a threat modeling exercise for a new microservices architecture. They are using the PASTA framework. After defining the business and technical objectives and identifying the technical scope, the next logical step is to analyze the identified threats and vulnerabilities. Which phase of PASTA does this correspond to?

  1. APhase 4: Vulnerability Analysis
  2. BPhase 3: Threat Analysis
  3. CPhase 1: Definition of the Scope
  4. DPhase 5: Attack Modeling
Show answer & explanation

Correct answer: B. Phase 3: Threat Analysis

In the PASTA framework, after defining the scope (Phase 1) and business/technical objectives (Phase 2), Phase 3 is dedicated to Threat Analysis, which involves identifying and understanding potential threats.

Why the other options are wrong

  • A. Phase 4, Vulnerability Analysis, follows Threat Analysis and focuses on identifying weaknesses that threats can exploit.
  • C. Phase 1 is defining the scope, which is stated as already completed.
  • D. Phase 5, Attack Modeling, comes after vulnerability analysis and aims to simulate attack paths.

PASTA Framework (Threat Modeling)

A 7-step risk-centric methodology for threat modeling that integrates business objectives with technical requirements.

  • Stands for Process for Attack Simulation and Threat Analysis.
  • Risk-centric approach.
  • Moves from business context to technical attacks.

Memory trick: PASTA: Start broad, then get specific about threats and attacks.

More Governance, Risk and Compliance questions