Module 3.2 Flashcards

1
Q

What are the factors of Treat Modeling

A

Threat actors, Threat source/agent, Threat event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

3 Threat Actors (Understanding the operational environment)

A

Motivation, Capabilities, Persistence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Categories of Threat Agents

A

Accidental, Structural, Environmental

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Actors in Accidental Threat Agent

A

User, Privileged user or administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Components of Structural Threat Agent

A

IT equipment, Environmental controls, Software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Examples of Environmental Threat Agent

A

Natural or man-made disaster, Unusual/rare natural events, Infrastructure failure (Telecommunications, Power)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

STRIDE model acronym

A

Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Escalation of Privilege

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

DREAD Acronym (Rating Thread Impact)

A

Damage, Reproducibility, Exploitability, Affected Users, Discoverability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Set of points on the boundary of a system, system element, or environment where an attacker can try to enter, cause an effect on, or extract data from

A

Attack Surface
Relative Attack Surface Quotient (RASQ)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How to define Attack Surface (C.P.M.T.L)

A

Creative, Persistent, Methodical, Technical, Log Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How to Validate Attack Surface

A

Penetration testing, Security Information and Event Management (SEIM) systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Threat Modeling Methodologies (Standards)

A

ISO/IEC 27005
ISO/IEC 31000
NIST SP 800-30 r1
HTRA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly