CISSP Software Development Security Practice Question
During a threat modeling session for a new online banking application, the team uses the STRIDE methodology. Which threat category addresses the risk of an attacker modifying transaction data in transit?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tampering
Tampering refers to the malicious modification of data. STRIDE's 'T' stands for Tampering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Information Disclosure
Why it's wrong here
Information Disclosure, in the context of an online banking application, refers to the unauthorized exposure of sensitive or confidential data to individuals or systems not permitted to access it. This could involve leaking account balances, transaction histories, personal identifiable information (PII), or even system architecture details, thereby compromising the confidentiality of user data and operational security. While a critical threat, it doesn't directly describe the *alteration* of data.
- ✓
Tampering
Why this is correct
Tampering specifically refers to the unauthorized modification or alteration of data, whether in transit or at rest, within an application or system. For an online banking application, this could manifest as an attacker changing transaction amounts, recipient details, account balances, or system logs, directly compromising the integrity of financial data and operational processes. This threat directly targets the trustworthiness and accuracy of information, making it a primary concern for financial systems.
- ✗
Elevation of Privilege
Why it's wrong here
Elevation of Privilege occurs when an attacker exploits a vulnerability to gain access rights or permissions beyond what they were initially authorized for, moving from a lower-privileged state to a higher one. In an online banking scenario, this might involve a regular user gaining administrative access or a limited user gaining access to another user's full account. While a severe threat, it focuses on unauthorized *access levels* rather than the direct *modification of data* itself.
- ✗
Spoofing
Why it's wrong here
Spoofing involves an attacker successfully impersonating a legitimate user, system, or entity to gain unauthorized access or deceive other components within the online banking environment. This could include phishing attacks to steal credentials, IP address spoofing, or DNS spoofing, aiming to bypass authentication mechanisms or misdirect traffic. Its primary focus is on faking identity or origin, distinct from the direct unauthorized alteration of data.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.