During a sprint planning session, a software architect is asked to incorporate security activities into the team's DevSecOps pipeline for a newly designed microservices-based payment application. The architect suggests conducting a structured threat-modeling workshop early in the design phase, involving developers, testers, and product owners. Which outcome BEST describes the primary purpose of performing threat modeling at this point in the software development lifecycle?
Identify, prioritize, and mitigate potential security threats before extensive coding begins
Develop detailed incident-response runbooks tailored to the anticipated threat landscape
Determine likely attackers and document their motivations for later penetration testing
Catalog known vulnerabilities in open-source and third-party libraries used by the project
Threat modeling is a structured technique that examines architecture, data flows, and trust boundaries to uncover, prioritize, and mitigate security threats before extensive coding begins. Performing it early shifts security left, letting teams design effective controls and avoid costly rework. Although knowing attacker motives, cataloging third-party component vulnerabilities, and writing incident-response plans are valuable, they represent narrower or later-stage activities rather than the main goal of threat modeling.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does threat modeling identify potential threats?
Open an interactive chat with Bash
What is STRIDE and how is it used in threat modeling?
Open an interactive chat with Bash
Why is it important to conduct threat modeling early in the development lifecycle?
Open an interactive chat with Bash
ISC2 CISSP
Software Development Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .