Courseiva
hardMultiple ChoiceObjective-mapped

CRISC Practice Question: A risk practitioner is conducting a threat…

A risk practitioner is conducting a threat modeling exercise for a new cloud-based application using the STRIDE methodology. Which of the following is the PRIMARY benefit of using STRIDE over a simple checklist?

⚠ Common exam trap

Watch out — candidates often confuse a structured methodology like STRIDE with a simple checklist, assuming any structured approach automatically ensures control consistency or risk quantification, when in fact STRIDE's primary benefit is its categorical coverage that reduces blind spots.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

It identifies threats by category, reducing the chance of missing key threat types

The STRIDE methodology categorizes threats into six specific types (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege). This structured approach ensures that the threat modeling exercise systematically covers each category, reducing the likelihood of overlooking entire classes of threats that a simple checklist might miss. For a cloud-based application, this is critical because threats like elevation of privilege or information disclosure can manifest in unique ways across shared infrastructure, and STRIDE forces the practitioner to consider each category explicitly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • It requires less expertise to perform

    Why it's wrong here

    STRIDE still requires expertise; it is not simpler than a checklist.

  • It automatically quantifies risk levels

    Why it's wrong here

    STRIDE is qualitative and does not quantify risk.

  • It ensures consistent application of controls

    Why it's wrong here

    Consistency is a benefit but not the primary one; checklists also provide consistency.

  • It identifies threats by category, reducing the chance of missing key threat types

    Why this is correct

    STRIDE's categories (Spoofing, Tampering, etc.) help ensure comprehensive threat identification.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.