Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium

During the 'design' phase of a cloud application's development lifecycle, a security architect is reviewing the proposed architecture for potential security vulnerabilities. Which of the following activities is most crucial at this stage to proactively identify and mitigate design-level security flaws?

  1. ARunning automated vulnerability scans on the cloud infrastructure.
  2. BConducting a threat modeling exercise for the application.
  3. CPerforming DAST on a deployed version of the application.
  4. DImplementing a bug bounty program for the production environment.
Show answer & explanation

Correct answer: B. Conducting a threat modeling exercise for the application.

Threat modeling is a structured approach to identify potential threats, vulnerabilities, and counter-measures during the design phase, allowing for proactive mitigation of architectural security flaws before code is even written.

Why the other options are wrong

  • A. Vulnerability scanning typically targets deployed infrastructure or known vulnerabilities, not design-level flaws, and usually happens later in the lifecycle.
  • C. DAST is performed on a *running* application, which occurs much later than the design phase.
  • D. A bug bounty program is for a *production* environment and is a reactive measure, not a proactive design-phase activity.

Threat Modeling

A structured process for identifying potential threats, vulnerabilities, and countermeasures at the design stage of software development.

  • Proactive security activity.
  • Focuses on identifying design flaws.
  • Helps prioritize security efforts.

Memory trick: Design Phase: 'Draw the Threats' before you build.

More Cloud Application Security questions