Courseiva
hardMultiple Choice

CRISC Practice Question: A risk practitioner is conducting a threat…

A risk practitioner is conducting a threat modeling exercise for a new cloud-based application using the STRIDE methodology. Which of the following is the PRIMARY benefit of using STRIDE over a simple checklist?

⚠ Common exam trap

Watch out — candidates often confuse a structured methodology like STRIDE with a simple checklist, assuming any structured approach automatically ensures control consistency or risk quantification, when in fact STRIDE's primary benefit is its categorical coverage that reduces blind spots.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It identifies threats by category, reducing the chance of missing key threat types

The STRIDE methodology categorizes threats into six specific types (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege). This structured approach ensures that the threat modeling exercise systematically covers each category, reducing the likelihood of overlooking entire classes of threats that a simple checklist might miss. For a cloud-based application, this is critical because threats like elevation of privilege or information disclosure can manifest in unique ways across shared infrastructure, and STRIDE forces the practitioner to consider each category explicitly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It requires less expertise to perform

    Why it's wrong here

    STRIDE demands structured expertise to map each spoofing, tampering and repudiation category onto a design; a checklist needs none, which is precisely why it misses threats. The claim inverts the trade-off. STRIDE is chosen when thorough, systematic threat enumeration across six categories matters, not when unskilled staff must perform a quick review.

  • ✗

    It automatically quantifies risk levels

    Why it's wrong here

    STRIDE produces qualitative threat categories, not numeric risk values; quantification requires separate likelihood and impact scoring. The stem asks for the benefit over a checklist, which is systematic category coverage, not measurement. Automated quantification belongs to quantitative tools such as FAIR, used when monetary loss estimates are required.

  • ✗

    It ensures consistent application of controls

    Why it's wrong here

    STRIDE provides a mnemonic taxonomy of threat categories; it does not enforce or guarantee consistent control application, which depends on governance and assessment. It is tempting because categorisation feels systematic. STRIDE's primary benefit is structured, repeatable identification of threats such as spoofing and tampering that checklists may omit.

  • ✓

    It identifies threats by category, reducing the chance of missing key threat types

    Why this is correct

    STRIDE structures threat discovery around six defined categories — spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege — so analysts systematically cover each, unlike an unstructured checklist that may omit entire threat classes.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.