CRISC IT Risk Identification Practice Question
During a threat modeling exercise for a new web application, the team uses STRIDE. Which threat type under STRIDE corresponds to an attacker modifying data in transit?
⚠ Common exam trap
CRISC often tests the STRIDE mnemonic and candidates frequently confuse Tampering (integrity) with Spoofing (authentication) or Repudiation (non-repudiation), especially when the scenario mentions an attacker 'intercepting' traffic, which could suggest multiple threat types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tampering
In STRIDE, Tampering refers to the unauthorized modification of data, whether at rest or in transit. An attacker modifying data in transit (e.g., man-in-the-middle altering a message) is the canonical example of Tampering. It violates integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Repudiation
Why it's wrong here
Repudiation concerns a party denying having performed an action, addressed through logging and non-repudiation controls, not modification of data in transit. It is tempting because both involve integrity of records, and Repudiation would be correct if the concern were a user later denying a transaction they genuinely performed.
- ✗
Information Disclosure
Why it's wrong here
Information Disclosure covers unauthorised exposure of data to those who should not see it, not its alteration during transmission. It is tempting because both are confidentiality-versus-integrity concerns on the same channel, and Information Disclosure would be correct if the attacker were reading traffic rather than changing it.
- ✓
Tampering
Why this is correct
Tampering covers unauthorised modification of data, including data in transit, so it directly matches the attacker altering packets between endpoints. Spoofing concerns identity falsification, Information Disclosure concerns exposure, and Repudiation concerns denying actions, none of which describe modifying data mid-transit.
- ✗
Spoofing
Why it's wrong here
Spoofing covers impersonating a legitimate entity, such as forging a user or host identity, not altering packet contents in flight. It is tempting because both are active attacks on a communication channel, and Spoofing would be the right STRIDE category if the attacker were pretending to be another principal rather than tampering with data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.