Question 1 of 30
The audit findings indicate a need to enhance the organization\'s threat modeling practices for its critical financial transaction processing system. The security team has limited resources and a tight deadline to deliver actionable security recommendations. Which of the following approaches would best address this situation?
Select a threat modeling technique that is specifically suited to the financial transaction system's architecture and business context, prioritizing the identification of threats most relevant to data integrity and confidentiality, and ensuring the output is directly actionable for the development team.
Implement a highly detailed and comprehensive threat modeling framework, such as STRIDE, across all layers of the system, regardless of the specific threat likelihood or impact, to ensure no potential vulnerability is overlooked.
Apply the same standardized threat modeling methodology that was used for the company's public-facing marketing website to the financial transaction system, as it has proven effective in the past.
Focus on generating an exhaustive list of all possible threats, including highly theoretical and improbable attack vectors, to demonstrate the team's thoroughness in identifying every conceivable risk to the system.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free