ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityMedium
A security architect is performing a threat modeling exercise for a new web application. The application will handle sensitive user data and interact with several backend services. Which of the following data flow diagram (DFD) elements primarily represents a potential point where an attacker could intercept or tamper with data?
- AProcess (e.g., 'User Authentication Module')
- BExternal Entity (e.g., 'Payment Gateway')
- CData Flow (e.g., 'Login Request')
- DData Store (e.g., 'User Database')
Show answer & explanationAnswer & explanation
Correct answer: C. Data Flow (e.g., 'Login Request')
In a Data Flow Diagram (DFD) for threat modeling, a 'Data Flow' represents the movement of data between components. This movement is a primary point where an attacker could intercept, read (disclosure), or modify (tampering) data while it is in transit, making it a critical element to analyze for security vulnerabilities.
Why the other options are wrong
- A. A 'Process' is where data is transformed; it's a point for processing vulnerabilities but not primarily for interception/tampering of data in transit.
- B. An 'External Entity' interacts with the system but is typically outside its control; while it can be a source of threats, the flow of data to/from it is where interception/tampering would occur.
- D. A 'Data Store' is where data resides; it's a point for data at rest vulnerabilities (e.g., unauthorized access), not primarily interception/tampering in transit.
DFD Data Flow
In Data Flow Diagrams (DFDs), a 'Data Flow' depicts the movement of information between processes, data stores, and external entities. It is represented by an arrow.
- Shows data in motion
- Represents communication channels
- Critical for identifying interception/tampering threats
Memory trick: Data flows are highways for threats, where interception sets its nets.