CISSP Software Development Security Practice Question
During a threat modeling session for a new online banking application, the team uses the STRIDE methodology. Which threat category addresses the risk of an attacker modifying transaction data in transit?
⚠ Common exam trap
CISSP often tests the mapping between STRIDE categories and the CIA/AAA properties they violate; candidates confuse Tampering (integrity) with Spoofing (authentication) or Information Disclosure (confidentiality) when the scenario mentions 'data in transit'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tampering
STRIDE's Tampering category covers unauthorized modification of data, whether at rest or in transit. Modifying transaction data in transit is the textbook definition of tampering, which violates integrity. The other categories map to different security properties: Information Disclosure to confidentiality, Spoofing to authentication, and Elevation of Privilege to authorization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Information Disclosure
Why it's wrong here
Information Disclosure, in the context of an online banking application, refers to the unauthorized exposure of sensitive or confidential data to individuals or systems not permitted to access it. This could involve leaking account balances, transaction histories, personal identifiable information (PII), or even system architecture details, thereby compromising the confidentiality of user data and operational security. While a critical threat, it doesn't directly describe the *alteration* of data.
- ✓
Tampering
Why this is correct
Tampering specifically refers to the unauthorized modification or alteration of data, whether in transit or at rest, within an application or system. For an online banking application, this could manifest as an attacker changing transaction amounts, recipient details, account balances, or system logs, directly compromising the integrity of financial data and operational processes. This threat directly targets the trustworthiness and accuracy of information, making it a primary concern for financial systems.
- ✗
Elevation of Privilege
Why it's wrong here
Elevation of Privilege occurs when an attacker exploits a vulnerability to gain access rights or permissions beyond what they were initially authorized for, moving from a lower-privileged state to a higher one. In an online banking scenario, this might involve a regular user gaining administrative access or a limited user gaining access to another user's full account. While a severe threat, it focuses on unauthorized *access levels* rather than the direct *modification of data* itself.
- ✗
Spoofing
Why it's wrong here
Spoofing involves an attacker successfully impersonating a legitimate user, system, or entity to gain unauthorized access or deceive other components within the online banking environment. This could include phishing attacks to steal credentials, IP address spoofing, or DNS spoofing, aiming to bypass authentication mechanisms or misdirect traffic. Its primary focus is on faking identity or origin, distinct from the direct unauthorized alteration of data.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.