Lecture 2 Flashcards

1
Q

What questions should you ask when you are threat modelling?

A

What are you building?
What can go wrong?
How can fix or avoid the threats?
Reflect on previous?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How can you potray what you are building and it’s assets?

A

Design a diagram.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What matters in a system? How can you categories a system and it’s assets?

A

External entities, proccesses data stores, the flow of data and trust boundaries.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is an external entity?

A

Anything that exists outside the system that interacts with the system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are proccesses within a system?

A

It is something a system does or is, an example of this is a program or a code. Or a way of communicating.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a data store?

A

Any form of data information depositry.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does STRIDE stand for?

A

Spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Spoofing.

A

.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Tampering.

A

T

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Repudiation.

A

R

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Information disclosure

A

I

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Denial of service.

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Elevation of privilege.

A

.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does META stand for?

A

Mitigation, eliminate, transfer or accept.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Mitigate.

A

.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Eliminate

A

.

17
Q

Transfer.

A

T

18
Q

Accept.

A

A