Courseiva
Software Development SecurityeasyMultiple ChoiceObjective-mapped

CISSP Software Development Security Practice Question

During the requirements gathering phase of a software development project, which threat modeling methodology is most commonly used to identify threats such as spoofing, tampering, and elevation of privilege?

⚠ Common exam trap

Candidates often confuse CVSS (a scoring system) or OCTAVE (a risk assessment framework) with threat modeling methodologies, but the question specifically asks for the methodology most commonly used to identify threat types like spoofing and tampering, which is STRIDE.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

STRIDE

STRIDE is a threat modeling methodology developed by Microsoft that categorizes threats into six types: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. During the requirements gathering phase, STRIDE is commonly used to systematically identify and classify potential security threats against each system component, making it the correct choice for identifying threats like spoofing, tampering, and elevation of privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • CVSS

    Why it's wrong here

    CVSS (Common Vulnerability Scoring System) is a standardized, open framework for communicating the characteristics and impacts of IT vulnerabilities. It provides a numerical score representing the severity of a vulnerability, allowing organizations to prioritize remediation efforts. However, CVSS is a post-discovery scoring system for *existing* vulnerabilities, not a proactive methodology for identifying potential threats during the design or requirements gathering phases of software development.

  • STRIDE

    Why this is correct

    STRIDE is a widely recognized threat modeling methodology developed by Microsoft, specifically designed to identify and categorize potential threats to a system during its design phase. Its acronym represents six distinct threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. These categories directly map to fundamental security properties like Authenticity, Integrity, Non-Repudiation, Confidentiality, Availability, and Authorization, making it highly effective for systematic threat identification in software.

  • OCTAVE

    Why it's wrong here

    OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is a comprehensive risk-based strategic assessment and planning framework, not a specific threat modeling methodology focused on software design categories. It helps organizations understand information security risks by identifying critical information assets, the threats to those assets, and the vulnerabilities that could expose them. OCTAVE focuses on organizational risk management and developing a protection strategy rather than detailing specific software-level threats like Spoofing or Tampering.

  • PASTA

    Why it's wrong here

    PASTA (Process for Attack Simulation and Threat Analysis) is a seven-stage, risk-centric threat modeling methodology that provides a structured approach to identifying, enumerating, and scoring threats. While it is a robust framework for understanding potential attacks and their business impact, it is distinct from STRIDE's specific categorization of threats against system properties. PASTA emphasizes an attacker-centric view, focusing on attack simulation and risk analysis to derive appropriate countermeasures, rather than a direct classification of threats into categories like Spoofing or Elevation of Privilege.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.