Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Shared Assessments CTPRP Exam - Topic 2 Question 15 Discussion

The BEST time in the SDLC process for an application service provider to perform Threat Modeling analysis is:
A) Before the application design and development activities begin
B) After the application vulnerability or penetration test is completed
C) After testing and before the deployment of the final code into production
D) Prior to the execution of a contract with each client

Shared Assessments CTPRP Exam - Topic 2 Question 15 Discussion

Actual exam question for Shared Assessments's CTPRP exam
Question #: 15
Topic #: 2
[All CTPRP Questions]

The BEST time in the SDLC process for an application service provider to perform Threat Modeling analysis is:

Show Suggested Answer Hide Answer
Suggested Answer: A

Threat modeling is a core element of the Microsoft Security Development Lifecycle (SDL) and a structured approach to identify, quantify, and address the security risks associated with an application12.Threat modeling helps to shape the application's design, meet the security objectives, and reduce risk1. The best time to perform threat modeling analysis is before the application design and development activities begin, as this allows the application service provider to:

Communicate about the security design of their systems1.

Analyze the design for potential security issues using a proven methodology1.

Suggest and manage mitigations for security issues1.

Incorporate security requirements into the design2.

Avoid costly rework or redesign later in the SDLC2.

Identify the most critical and relevant threats to focus on2.Reference:1: Microsoft Security Development Lifecycle Threat Modelling12: Threat Modeling Process | OWASP Foundation2


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel