Courseiva
Software Development SecuritymediumMultiple ChoiceObjective-mapped

CISSP Software Development Security Practice Question

During the requirements gathering phase of a secure SDLC, the team uses a threat modeling approach that focuses on identifying threats such as spoofing, tampering, and denial of service. Which threat modeling methodology is being employed?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

STRIDE

STRIDE is a threat modeling framework developed by Microsoft that categorizes threats into six categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • PASTA

    Why it's wrong here

    PASTA (Process for Attack Simulation and Threat Analysis) is a seven-step, risk-centric threat modeling methodology that analyzes applications from an attacker's perspective to identify and prioritize threats based on business impact and technical exploitation. While comprehensive in its risk assessment, PASTA does not inherently utilize or categorize threats according to the specific STRIDE mnemonic (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) as its primary classification framework.

  • Trike

    Why it's wrong here

    Trike is an open-source, risk-based threat modeling methodology that focuses on defining a security requirements model, a threat model, and a risk model, emphasizing the assignment of acceptable risk levels to assets. It provides a structured approach for identifying and prioritizing threats based on risk and creating defensive countermeasures. However, Trike employs its own distinct framework for threat identification and analysis, which does not directly align with or incorporate the STRIDE categorization scheme.

  • STRIDE

    Why this is correct

    STRIDE is a mnemonic developed by Microsoft that provides a systematic framework for categorizing and identifying common types of threats against software and systems. Each letter represents a specific threat category: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. This framework is exceptionally useful during the requirements gathering phase of the SDLC to proactively identify potential vulnerabilities and design security controls that directly mitigate these well-defined threat types.

  • OCTAVE

    Why it's wrong here

    OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is a comprehensive, three-phase risk assessment framework designed to help organizations identify and manage information security risks from an organizational perspective. It focuses on involving business units to identify critical information assets and their associated threats and vulnerabilities. While crucial for overall enterprise risk management, OCTAVE is a broader risk assessment methodology and does not specifically employ or integrate the STRIDE threat categorization framework for detailed application or system-level threat modeling.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.