hardMultiple Choice
CRISC Practice Question: A risk practitioner is conducting a threat…
A risk practitioner is conducting a threat modeling exercise for a new cloud-based application using the STRIDE methodology. Which of the following is the PRIMARY benefit of using STRIDE over a simple checklist?
⚠ Common exam trap
Watch out — candidates often confuse a structured methodology like STRIDE with a simple checklist, assuming any structured approach automatically ensures control consistency or risk quantification, when in fact STRIDE's primary benefit is its categorical coverage that reduces blind spots.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It identifies threats by category, reducing the chance of missing key threat types
The STRIDE methodology categorizes threats into six specific types (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege). This structured approach ensures that the threat modeling exercise systematically covers each category, reducing the likelihood of overlooking entire classes of threats that a simple checklist might miss. For a cloud-based application, this is critical because threats like elevation of privilege or information disclosure can manifest in unique ways across shared infrastructure, and STRIDE forces the practitioner to consider each category explicitly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It requires less expertise to perform
Why it's wrong here
STRIDE demands structured expertise to map each spoofing, tampering and repudiation category onto a design; a checklist needs none, which is precisely why it misses threats. The claim inverts the trade-off. STRIDE is chosen when thorough, systematic threat enumeration across six categories matters, not when unskilled staff must perform a quick review.
- ✗
It automatically quantifies risk levels
Why it's wrong here
STRIDE produces qualitative threat categories, not numeric risk values; quantification requires separate likelihood and impact scoring. The stem asks for the benefit over a checklist, which is systematic category coverage, not measurement. Automated quantification belongs to quantitative tools such as FAIR, used when monetary loss estimates are required.
- ✗
It ensures consistent application of controls
Why it's wrong here
STRIDE provides a mnemonic taxonomy of threat categories; it does not enforce or guarantee consistent control application, which depends on governance and assessment. It is tempting because categorisation feels systematic. STRIDE's primary benefit is structured, repeatable identification of threats such as spoofing and tampering that checklists may omit.
- ✓
It identifies threats by category, reducing the chance of missing key threat types
Why this is correct
STRIDE structures threat discovery around six defined categories — spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege — so analysts systematically cover each, unlike an unstructured checklist that may omit entire threat classes.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.