Self-assessment questions
- What is a threat model?
- A type of malware
- A cybersecurity certification
- A systematic approach to identifying and evaluating potential security threats
- A hardware security device
- What does the first “D” mean in the DREAD threat modeling framework?
- Data encryption
- Damage potential
- Design
- Detection
- What does the “T” in STRIDE stand for in the context of threat modeling?
- Time
- Tampering
- Trespassing
- Trust
- In the STRIDE threat model, what does the “R” represent?
- Reliability
- Remote execution
- Repudiation
- Reusability
- Suppose you are analyzing a potential security breach using an attack tree. In the attack tree, you have identified two possible attack paths to compromise a sensitive database:
Path 1:
The attacker gains physical access to the server room.
The attacker compromises the server hardware.
The attacker accesses the sensitive database.
Path 2:
The attacker exploits a known software vulnerability on the...