ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium
A technology company is developing a new mobile application that will handle sensitive user data. Before deployment, the development team conducts a structured analysis to identify potential vulnerabilities and threats from an attacker's perspective, without requiring actual code review. They prioritize these findings based on potential impact and likelihood. Which methodology are they most likely employing?
- ASecurity Auditing
- BVulnerability Scanning
- CPenetration Testing
- DThreat Modeling
Show answer & explanationAnswer & explanation
Correct answer: D. Threat Modeling
The description of a structured analysis to identify vulnerabilities and threats from an attacker's perspective, prioritizing based on impact and likelihood, without necessarily reviewing code, perfectly aligns with threat modeling methodologies.
Why the other options are wrong
- A. Security auditing involves reviewing controls and processes for compliance and effectiveness.
- B. Vulnerability scanning identifies known vulnerabilities automatically.
- C. Penetration testing involves actively exploiting vulnerabilities.
Threat Modeling
A structured approach to identify, quantify, and address security risks in a system or application design.
- Proactive security measure, typically done early in SDLC.
- Focuses on 'what can go wrong' from an attacker's view.
- Helps prioritize security efforts and design effective countermeasures.
Memory trick: Find the weaknesses before they find you: Scan, Model, PenTest, Audit.