Courseiva
Software Development SecuritymediumMultiple ChoiceObjective-mapped

CISSP Software Development Security Practice Question

During a threat modeling session for a new online banking application, the team uses the STRIDE methodology. Which threat category addresses the risk of an attacker modifying transaction data in transit?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Tampering

Tampering refers to the malicious modification of data. STRIDE's 'T' stands for Tampering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Information Disclosure

    Why it's wrong here

    Information Disclosure, in the context of an online banking application, refers to the unauthorized exposure of sensitive or confidential data to individuals or systems not permitted to access it. This could involve leaking account balances, transaction histories, personal identifiable information (PII), or even system architecture details, thereby compromising the confidentiality of user data and operational security. While a critical threat, it doesn't directly describe the *alteration* of data.

  • Tampering

    Why this is correct

    Tampering specifically refers to the unauthorized modification or alteration of data, whether in transit or at rest, within an application or system. For an online banking application, this could manifest as an attacker changing transaction amounts, recipient details, account balances, or system logs, directly compromising the integrity of financial data and operational processes. This threat directly targets the trustworthiness and accuracy of information, making it a primary concern for financial systems.

  • Elevation of Privilege

    Why it's wrong here

    Elevation of Privilege occurs when an attacker exploits a vulnerability to gain access rights or permissions beyond what they were initially authorized for, moving from a lower-privileged state to a higher one. In an online banking scenario, this might involve a regular user gaining administrative access or a limited user gaining access to another user's full account. While a severe threat, it focuses on unauthorized *access levels* rather than the direct *modification of data* itself.

  • Spoofing

    Why it's wrong here

    Spoofing involves an attacker successfully impersonating a legitimate user, system, or entity to gain unauthorized access or deceive other components within the online banking environment. This could include phishing attacks to steal credentials, IP address spoofing, or DNS spoofing, aiming to bypass authentication mechanisms or misdirect traffic. Its primary focus is on faking identity or origin, distinct from the direct unauthorized alteration of data.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.