hardMultiple ChoiceObjective-mapped
CRISC Practice Question: A risk practitioner is conducting a threat…
A risk practitioner is conducting a threat modeling exercise for a new cloud-based application using the STRIDE methodology. Which of the following is the PRIMARY benefit of using STRIDE over a simple checklist?
⚠ Common exam trap
Watch out — candidates often confuse a structured methodology like STRIDE with a simple checklist, assuming any structured approach automatically ensures control consistency or risk quantification, when in fact STRIDE's primary benefit is its categorical coverage that reduces blind spots.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It identifies threats by category, reducing the chance of missing key threat types
The STRIDE methodology categorizes threats into six specific types (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege). This structured approach ensures that the threat modeling exercise systematically covers each category, reducing the likelihood of overlooking entire classes of threats that a simple checklist might miss. For a cloud-based application, this is critical because threats like elevation of privilege or information disclosure can manifest in unique ways across shared infrastructure, and STRIDE forces the practitioner to consider each category explicitly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It requires less expertise to perform
Why it's wrong here
STRIDE still requires expertise; it is not simpler than a checklist.
- ✗
It automatically quantifies risk levels
Why it's wrong here
STRIDE is qualitative and does not quantify risk.
- ✗
It ensures consistent application of controls
Why it's wrong here
Consistency is a benefit but not the primary one; checklists also provide consistency.
- ✓
It identifies threats by category, reducing the chance of missing key threat types
Why this is correct
STRIDE's categories (Spoofing, Tampering, etc.) help ensure comprehensive threat identification.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.