CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium
A security architect is performing a threat modeling exercise for a new cloud-native application that processes sensitive customer data. The architect wants to systematically identify potential threats and vulnerabilities throughout the application's lifecycle. Which of the following threat modeling methodologies is best suited for this purpose, providing a structured approach from design to deployment?
- ASTRIDE
- BDREAD
- CPASTA
- DCVSS
Show answer & explanationAnswer & explanation
Correct answer: C. PASTA
PASTA (Process for Attack Simulation and Threat Analysis) is a seven-stage, risk-centric methodology that provides a structured approach to integrate threat modeling into the application development lifecycle, covering everything from business objectives to technical analysis and countermeasure selection.
Why the other options are wrong
- A. STRIDE is a threat categorization model, not a full lifecycle methodology.
- B. DREAD is a risk rating model, often used in conjunction with STRIDE, not a complete threat modeling methodology.
- D. CVSS (Common Vulnerability Scoring System) is for rating the severity of vulnerabilities, not a threat modeling methodology.
PASTA (Process for Attack Simulation and Threat Analysis)
A risk-centric threat modeling framework that guides organizations through a seven-stage process to identify, enumerate, and score threats, and then analyze potential attacks to determine appropriate countermeasures.
- Integrates threat modeling into the software development lifecycle.
- Focuses on attacker centric perspective and risk analysis.
- Provides a structured, repeatable process for threat identification and mitigation.
Memory trick: PASTA: A full-course meal for security analysis.