During a risk assessment, the risk practitioner is identifying threats to an application. Which threat modeling technique is specifically designed to analyze application threats using categories such as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
STRIDE is Microsoft's threat modelling framework whose six mnemonic categories — Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service and Elevation of Privilege — map directly onto the stem's listed threat types, making it the technique explicitly designed for categorising application threats.
Why this answer
STRIDE is a threat modeling methodology developed by Microsoft that categorizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It is specifically designed to analyze application threats using these categories, making it the correct answer.
Exam trap
The trap is confusing STRIDE with other threat modeling methodologies like PASTA or TRIKE; candidates must memorize the STRIDE acronym and its categories.
How to eliminate wrong answers
Option B is wrong because VAST (Visual, Agile, and Simple Threat) is a threat modeling methodology focused on scalability and integration with Agile, but it does not use the STRIDE categories. Option C is wrong because TRIKE is a risk-based threat modeling methodology that uses a requirements model and an implementation model, but it does not use the STRIDE mnemonic. Option D is wrong because PASTA (Process for Attack Simulation and Threat Analysis) is a seven-step risk-centric threat modeling methodology, but it does not use the STRIDE categories.