CRISC IT Risk Identification Practice Question
An organization uses the PASTA threat modeling methodology. In which stage would the team identify threat agents and their capabilities?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat analysis
PASTA's third stage involves profiling threat agents and their capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define objectives
Why it's wrong here
Defining objectives sets business goals and scope, not adversary identification. Tempting because scoping feels like where threats are catalogued, but PASTA identifies threat agents and their capabilities during stage two, threat analysis, where intelligence on actors is mapped to the application.
- ✓
Threat analysis
Why this is correct
Threat analysis is the PASTA stage that enumerates threat agents, their capabilities, motivations and objectives, mapping them against the application's assets and attack surface. This directly satisfies the stem's requirement to identify threat agents and capabilities, distinguishing it from decomposition, attack modelling and risk/impact analysis stages.
- ✗
Vulnerability analysis
Why it's wrong here
Vulnerability analysis maps weaknesses to the threat model; it does not enumerate threat agents or their capabilities. Tempting because vulnerabilities and threats are often conflated, but PASTA places agent identification in stage two, threat analysis, before vulnerabilities are analysed in stage four.
- ✗
Decompose application
Why it's wrong here
Decompose application is PASTA's first stage, where the team maps components, data flows and trust boundaries to define the attack surface. Threat agents and their capabilities are enumerated in the later threat analysis stage, so this option answers a different stage's purpose.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.