ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityMedium

A security architect is performing a threat modeling exercise for a new web application. The application will handle sensitive user data and interact with several backend services. Which of the following data flow diagram (DFD) elements primarily represents a potential point where an attacker could intercept or tamper with data?

  1. AProcess (e.g., 'User Authentication Module')
  2. BExternal Entity (e.g., 'Payment Gateway')
  3. CData Flow (e.g., 'Login Request')
  4. DData Store (e.g., 'User Database')
Show answer & explanation

Correct answer: C. Data Flow (e.g., 'Login Request')

In a Data Flow Diagram (DFD) for threat modeling, a 'Data Flow' represents the movement of data between components. This movement is a primary point where an attacker could intercept, read (disclosure), or modify (tampering) data while it is in transit, making it a critical element to analyze for security vulnerabilities.

Why the other options are wrong

  • A. A 'Process' is where data is transformed; it's a point for processing vulnerabilities but not primarily for interception/tampering of data in transit.
  • B. An 'External Entity' interacts with the system but is typically outside its control; while it can be a source of threats, the flow of data to/from it is where interception/tampering would occur.
  • D. A 'Data Store' is where data resides; it's a point for data at rest vulnerabilities (e.g., unauthorized access), not primarily interception/tampering in transit.

DFD Data Flow

In Data Flow Diagrams (DFDs), a 'Data Flow' depicts the movement of information between processes, data stores, and external entities. It is represented by an arrow.

  • Shows data in motion
  • Represents communication channels
  • Critical for identifying interception/tampering threats

Memory trick: Data flows are highways for threats, where interception sets its nets.

More Software Development Security questions