ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A DevSecOps team is building a multitenant SaaS application in the public cloud using an iterative Agile SDLC. To avoid costly re-work, the security architect wants to introduce threat modeling at the earliest point when the system's architecture is sufficiently defined but before any code is written. According to a traditional SDLC, which phase should the team target for this activity?
Threat modeling provides the most value when it is performed once the system architecture has taken shape but before implementation begins, allowing security requirements and design changes to be incorporated with minimal cost. In a classic SDLC, this aligns with the design (or architecture) phase, which follows requirements analysis and precedes coding. Performing threat modeling later, during implementation or testing, uncovers issues after code has been written, leading to greater re-work, while performing it during initial requirements gathering is premature because architectural details needed to model threats are not yet available.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is threat modeling important in the design phase?
Open an interactive chat with Bash
What is the difference between Agile SDLC and traditional SDLC in terms of threat modeling?
Open an interactive chat with Bash
What tools or techniques are commonly used for threat modeling in the design phase?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .