Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
During the 'design' phase of a cloud application's development lifecycle, a security architect is reviewing the proposed architecture for potential security vulnerabilities. Which of the following activities is most crucial at this stage to proactively identify and mitigate design-level security flaws?
- ARunning automated vulnerability scans on the cloud infrastructure.
- BConducting a threat modeling exercise for the application.
- CPerforming DAST on a deployed version of the application.
- DImplementing a bug bounty program for the production environment.
Show answer & explanationAnswer & explanation
Correct answer: B. Conducting a threat modeling exercise for the application.
Threat modeling is a structured approach to identify potential threats, vulnerabilities, and counter-measures during the design phase, allowing for proactive mitigation of architectural security flaws before code is even written.
Why the other options are wrong
- A. Vulnerability scanning typically targets deployed infrastructure or known vulnerabilities, not design-level flaws, and usually happens later in the lifecycle.
- C. DAST is performed on a *running* application, which occurs much later than the design phase.
- D. A bug bounty program is for a *production* environment and is a reactive measure, not a proactive design-phase activity.
Threat Modeling
A structured process for identifying potential threats, vulnerabilities, and countermeasures at the design stage of software development.
- Proactive security activity.
- Focuses on identifying design flaws.
- Helps prioritize security efforts.
Memory trick: Design Phase: 'Draw the Threats' before you build.