Domain 2 - Threat Modeling and Methodologies

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/12

flashcard set

Earn XP

Description and Tags

Flashcards covering key concepts and terminology related to threat modeling, including methods STRIDE and PASTA.

Last updated 8:24 PM on 12/8/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

13 Terms

1
New cards

Threat Modeling

The systematic identification, enumeration, and prioritization of threats related to an asset.

2
New cards

STRIDE

A threat modeling methodology developed by Microsoft that stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

3
New cards

Spoofing

An attack where an attacker pretends to be someone else to gain unauthorized access, violating authentication.

4
New cards

Tampering

Modification of data at rest or in transit by an attacker, violating integrity.

5
New cards

Repudiation

An attack where an action is performed on the system that cannot be attributed to the attacker, violating non-repudiation.

6
New cards

Information Disclosure

An attack where an attacker gains access to information they should not, violating confidentiality.

7
New cards

Denial of Service (DoS)

An attack that prevents authorized users from accessing a system or resource, violating availability.

8
New cards

Elevation of Privilege

An attack to gain elevated access from regular user level to root or administrative level, violating authorization.

9
New cards

PASTA

The Process for Attack Simulation and Threat Analysis, a risk-centric approach to threat modeling that considers business aspects of a system.

10
New cards

Objectives (in PASTA)

The initial phase in the PASTA method where the goals of the threat analysis are defined.

11
New cards

Application Decomposition

A step in PASTA where the system is broken down into its components for analysis.

12
New cards

Risk and Impact Analysis

A step in the PASTA methodology that assesses the potential risks and impacts of identified threats.

13
New cards

Comparison of STRIDE and PASTA

Use STRIDE for quicker, simpler analyses; use PASTA for thorough, risk-based analyses that consider both technical and business perspectives.