Domain 2 - Threat Modeling and Methodologies

0.0(0)
studied byStudied by 0 people
0.0(0)
linked notesView linked note
full-widthCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/12

flashcard set

Earn XP

Description and Tags

Flashcards covering key concepts and terminology related to threat modeling, including methods STRIDE and PASTA.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

13 Terms

1
New cards

Threat Modeling

The systematic identification, enumeration, and prioritization of threats related to an asset.

2
New cards

STRIDE

A threat modeling methodology developed by Microsoft that stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

3
New cards

Spoofing

An attack where an attacker pretends to be someone else to gain unauthorized access, violating authentication.

4
New cards

Tampering

Modification of data at rest or in transit by an attacker, violating integrity.

5
New cards

Repudiation

An attack where an action is performed on the system that cannot be attributed to the attacker, violating non-repudiation.

6
New cards

Information Disclosure

An attack where an attacker gains access to information they should not, violating confidentiality.

7
New cards

Denial of Service (DoS)

An attack that prevents authorized users from accessing a system or resource, violating availability.

8
New cards

Elevation of Privilege

An attack to gain elevated access from regular user level to root or administrative level, violating authorization.

9
New cards

PASTA

The Process for Attack Simulation and Threat Analysis, a risk-centric approach to threat modeling that considers business aspects of a system.

10
New cards

Objectives (in PASTA)

The initial phase in the PASTA method where the goals of the threat analysis are defined.

11
New cards

Application Decomposition

A step in PASTA where the system is broken down into its components for analysis.

12
New cards

Risk and Impact Analysis

A step in the PASTA methodology that assesses the potential risks and impacts of identified threats.

13
New cards

Comparison of STRIDE and PASTA

Use STRIDE for quicker, simpler analyses; use PASTA for thorough, risk-based analyses that consider both technical and business perspectives.