CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium

During a threat modeling exercise for a new mobile application, the development team identifies a potential vulnerability where an attacker could intercept API calls between the app and the backend server. The team determines that implementing mutual TLS authentication and API gateway rate limiting would effectively address this risk. Which phase of the STRIDE threat modeling methodology does this activity align with?

  1. AAnalyze Risk
  2. BDetermine Mitigations
  3. CIdentify Threats
  4. DIdentify Vulnerabilities
Show answer & explanation

Correct answer: B. Determine Mitigations

The STRIDE methodology includes phases for identifying threats, vulnerabilities, and then determining appropriate mitigations. In this scenario, after identifying the threat (API interception) and implicitly the vulnerability (lack of strong authentication/rate limiting), the team is now deciding on specific security controls (mutual TLS, rate limiting) to address it. This falls under determining mitigations.

Why the other options are wrong

  • A. Analyzing risk typically involves assessing the likelihood and impact of identified threats and vulnerabilities, which informs the prioritization of mitigations, but the act of choosing controls is mitigation.
  • C. Identifying threats involves categorizing potential attacks using STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege), which was an earlier step.
  • D. Identifying vulnerabilities involves pinpointing weaknesses in the system that attackers could exploit, which would precede or be concurrent with determining mitigations.

STRIDE (Threat Modeling)

A mnemonic used in threat modeling to categorize and identify threats: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It helps in systematically analyzing potential security weaknesses.

  • Categorizes threats into six types.
  • Used during the threat modeling process.
  • Helps ensure comprehensive threat analysis.

Memory trick: D-I-D-A: Diagram, Identify, Determine, Analyze.

More Governance, Risk and Compliance questions