CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceEasy
A security architect is performing a threat modeling exercise for a new cloud-native application that processes sensitive customer data. The architect is particularly concerned about vulnerabilities that could lead to unauthorized data disclosure, data alteration, or denial of service. Which threat modeling framework would BEST help the architect systematically identify these types of threats?
- APASTA
- BOCTAVE
- CDREAD
- DSTRIDE
Show answer & explanationAnswer & explanation
Correct answer: D. STRIDE
STRIDE is a widely used threat modeling framework that categorizes threats into six types: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. This framework directly addresses the architect's concerns about unauthorized data disclosure, data alteration (tampering), and denial of service.
Why the other options are wrong
- A. PASTA is a seven-step risk-centric methodology, more comprehensive but less direct for initial threat categorization.
- B. OCTAVE is an organizational risk management framework, not a direct threat categorization method for applications.
- C. DREAD is a risk assessment model (Damage, Reproducibility, Exploitability, Affected users, Discoverability), not a threat categorization framework.
STRIDE Threat Modeling
A mnemonic used to categorize and identify threats to applications and systems.
- Developed by Microsoft.
- Helps ensure a comprehensive approach to threat identification.
- Each letter represents a specific threat category.
Memory trick: STRIDE through threats to find their core.