Courseiva
IT Risk Identification →hardMultiple Choice

CRISC IT Risk Identification Practice Question

An organization uses the PASTA threat modeling methodology for a new e-commerce platform. Which of the following is a key characteristic of PASTA?

⚠ Common exam trap

Watch out — candidates often confuse PASTA with STRIDE or generic agile threat modeling — candidates pick 'requirements-based' or 'visual diagrams' because those sound like threat modeling, missing PASTA's business-impact and attack-simulation identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It emphasizes business impact analysis and attack simulation

PASTA (Process for Attack Simulation and Threat Analysis) is a seven-stage, risk-centric threat modeling methodology that explicitly aligns technical threats with business objectives. Its defining characteristic is that it starts from business impact analysis and uses attack simulation to validate which threats actually matter. This business-impact-first, adversary-simulation approach distinguishes it from code-centric or diagram-centric models.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It is a requirements-based model that uses a risk management perspective

    Why it's wrong here

    PASTA is an attacker-centric, seven-stage methodology built around simulating real attacks and business impact, not a requirements-based model. Requirements-based threat modelling describes approaches such as STRIDE-per-element applied to design specifications. PASTA would be chosen where attacker perspective and risk quantification are the priority.

  • ✗

    It uses visual diagrams to represent threats in an agile manner

    Why it's wrong here

    PASTA is a seven-stage, risk-centric methodology producing attack simulations and business impact analysis, not agile visual threat diagrams. Visual diagramming in sprints describes LINDDUN or attack trees used in rapid iterations. PASTA would be chosen where aligning threat analysis to business risk and executive reporting matters.

  • ✓

    It emphasizes business impact analysis and attack simulation

    Why this is correct

    PASTA is a seven-stage, attacker-centric methodology that aligns threat modelling with business objectives, using business impact analysis and attack simulation to quantify risk against organisational goals. This distinguishes it from code-centric approaches such as STRIDE, which categorise threats rather than simulate attacks.

  • ✗

    It focuses on agile development and integrates with DevSecOps

    Why it's wrong here

    PASTA is a risk-centric, seven-stage methodology aligned to business objectives, not an agile or DevSecOps integration framework. Agile-integrated threat modelling describes approaches such as threat modelling in CI/CD pipelines. PASTA would be selected where business risk alignment and attacker simulation drive the analysis.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.