Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard

A software development team is adopting a 'secure by design' approach for their new application. During the architecture phase, they are focusing on identifying potential attack surfaces and designing controls to mitigate risks before any code is written. Which activity is a critical part of implementing 'secure by design' at this early stage?

  1. AVulnerability Scanning
  2. BThreat Modeling
  3. CIncident Response Planning
  4. DPenetration Testing
Show answer & explanation

Correct answer: B. Threat Modeling

Threat modeling is a structured approach to identifying potential threats, vulnerabilities, and attacks against a system, application, or process. It is performed during the design phase ('before any code is written') to proactively integrate security controls, which aligns perfectly with the 'secure by design' principle.

Why the other options are wrong

  • A. Vulnerability scanning is usually done on deployed or developed code, not during the architecture phase.
  • C. Incident response planning is about what to do after a breach, not about preventing vulnerabilities in the design.
  • D. Penetration testing is typically performed on a live or near-live system, much later in the development lifecycle.

Threat Modeling

A structured process for identifying, quantifying, and mitigating security threats relevant to a system during its design and development phases. It helps in proactively building security into the architecture.

  • Performed early in the Software Development Life Cycle (SDLC).
  • Helps identify potential attack vectors and vulnerabilities.
  • Involves analyzing the system's architecture, data flows, and trust boundaries.
  • A key component of the 'secure by design' principle.

Memory trick: Design Securely, Model Threats Early

More Security Concepts questions