Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

When using STRIDE for threat modeling, which threat category involves an attacker gaining unauthorized access to a system by pretending to be a legitimate user?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Spoofing

Spoofing in STRIDE refers to impersonating something or someone else to gain unauthorized access, such as using stolen credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Repudiation

    Why it's wrong here

    Repudiation concerns denying having performed an action, so it fails this scenario because no identity is assumed. It is tempting because it also involves authentication-adjacent logging gaps, and it would be correct where non-repudiation controls, such as signed audit trails, are being assessed rather than impersonation.

  • ✗

    Information Disclosure

    Why it's wrong here

    Information Disclosure covers exposure of data to those not authorised to see it, not impersonation. An attacker masquerading as a legitimate user is Spoofing, so this category describes the consequence rather than the identity-deception threat.

  • ✗

    Tampering

    Why it's wrong here

    Tampering covers unauthorised modification of data or code in transit or at rest, so it fails a scenario defined by impersonating a legitimate user. It tempts because it is a genuine STRIDE category, and it would be correct where an attacker alters messages, files or database records rather than adopting another identity.

  • ✓

    Spoofing

    Why this is correct

    Spoofing covers impersonating a legitimate user, system or component to gain unauthorised access. Pretending to be a valid user directly matches this STRIDE category, unlike Tampering, Repudiation, Information Disclosure, Denial of Service or Elevation of Privilege.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.