CRISC IT Risk Identification Practice Question
When using STRIDE for threat modeling, which threat category involves an attacker gaining unauthorized access to a system by pretending to be a legitimate user?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spoofing
Spoofing in STRIDE refers to impersonating something or someone else to gain unauthorized access, such as using stolen credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Repudiation
Why it's wrong here
Repudiation concerns denying having performed an action, so it fails this scenario because no identity is assumed. It is tempting because it also involves authentication-adjacent logging gaps, and it would be correct where non-repudiation controls, such as signed audit trails, are being assessed rather than impersonation.
- ✗
Information Disclosure
Why it's wrong here
Information Disclosure covers exposure of data to those not authorised to see it, not impersonation. An attacker masquerading as a legitimate user is Spoofing, so this category describes the consequence rather than the identity-deception threat.
- ✗
Tampering
Why it's wrong here
Tampering covers unauthorised modification of data or code in transit or at rest, so it fails a scenario defined by impersonating a legitimate user. It tempts because it is a genuine STRIDE category, and it would be correct where an attacker alters messages, files or database records rather than adopting another identity.
- ✓
Spoofing
Why this is correct
Spoofing covers impersonating a legitimate user, system or component to gain unauthorised access. Pretending to be a valid user directly matches this STRIDE category, unlike Tampering, Repudiation, Information Disclosure, Denial of Service or Elevation of Privilege.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.