ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization is using the PASTA (Process for Attack Simulation and Threat Analysis) methodology while designing a new serverless payment API on a public cloud. The team has finished diagramming data flows and defining trust boundaries for every microservice (the completion of Stage 3). Their next task is to build an inventory of potential threat agents, associate attack vectors with each component, and estimate likelihood. According to the PASTA model, which stage should they perform now?
In PASTA, Stage 3 is Application Decomposition and Analysis, where the system is broken down into components, data flows, and trust boundaries. The subsequent Stage 4-Threat Analysis-focuses on identifying threat agents, mapping attack vectors to each component, and assigning probability or motivation scores. Stage 5 (Weakness and Vulnerability Analysis) comes later, using the threat inventory to locate exploitable flaws. Stage 6 (Attack Modeling and Simulation) builds attack trees or simulations after vulnerabilities are known, and Stage 2 (Define Technical Scope) should already have been completed before any decomposition work. Therefore, Stage 4 Threat Analysis is the correct next step.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the primary goal of Stage 4 - Threat Analysis in the PASTA methodology?
Open an interactive chat with Bash
What are trust boundaries in the context of PASTA Stage 3?
Open an interactive chat with Bash
How are attack vectors assigned to components in PASTA's Stage 4 - Threat Analysis?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .