CRISC IT Risk Identification Practice Question
An organization uses the PASTA threat modeling methodology for a new e-commerce platform. Which of the following is a key characteristic of PASTA?
⚠ Common exam trap
Watch out — candidates often confuse PASTA with STRIDE or generic agile threat modeling — candidates pick 'requirements-based' or 'visual diagrams' because those sound like threat modeling, missing PASTA's business-impact and attack-simulation identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It emphasizes business impact analysis and attack simulation
PASTA (Process for Attack Simulation and Threat Analysis) is a seven-stage, risk-centric threat modeling methodology that explicitly aligns technical threats with business objectives. Its defining characteristic is that it starts from business impact analysis and uses attack simulation to validate which threats actually matter. This business-impact-first, adversary-simulation approach distinguishes it from code-centric or diagram-centric models.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is a requirements-based model that uses a risk management perspective
Why it's wrong here
PASTA is an attacker-centric, seven-stage methodology built around simulating real attacks and business impact, not a requirements-based model. Requirements-based threat modelling describes approaches such as STRIDE-per-element applied to design specifications. PASTA would be chosen where attacker perspective and risk quantification are the priority.
- ✗
It uses visual diagrams to represent threats in an agile manner
Why it's wrong here
PASTA is a seven-stage, risk-centric methodology producing attack simulations and business impact analysis, not agile visual threat diagrams. Visual diagramming in sprints describes LINDDUN or attack trees used in rapid iterations. PASTA would be chosen where aligning threat analysis to business risk and executive reporting matters.
- ✓
It emphasizes business impact analysis and attack simulation
Why this is correct
PASTA is a seven-stage, attacker-centric methodology that aligns threat modelling with business objectives, using business impact analysis and attack simulation to quantify risk against organisational goals. This distinguishes it from code-centric approaches such as STRIDE, which categorise threats rather than simulate attacks.
- ✗
It focuses on agile development and integrates with DevSecOps
Why it's wrong here
PASTA is a risk-centric, seven-stage methodology aligned to business objectives, not an agile or DevSecOps integration framework. Agile-integrated threat modelling describes approaches such as threat modelling in CI/CD pipelines. PASTA would be selected where business risk alignment and attacker simulation drive the analysis.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.