ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an architectural design review, a colleague proposes to use the Common Vulnerability Scoring System (CVSS) as the team's sole threat-modeling approach, arguing it will identify all possible threats and guide mitigation planning. According to secure software lifecycle best practices, what is the most appropriate response?
Recommend adding a methodology such as STRIDE, explaining that CVSS only scores severity after vulnerabilities are identified rather than performing threat discovery.
Support the idea, because CVSS fully covers identifying and prioritizing threats across the system lifecycle.
Accept the plan but insist CVSS be applied early so the team can skip other time-consuming threat-modeling activities.
Propose replacing CVSS with the DREAD model, since DREAD is specifically designed for end-to-end threat modeling.
CVSS is an industry-standard framework for rating the severity of already discovered vulnerabilities; it does not help a team discover or model potential threats during design. Effective threat modeling requires a methodology, such as STRIDE or PASTA, that systematically identifies assets, attackers, and attack vectors before any scoring takes place. Therefore, the team should supplement CVSS with a true threat-modeling approach. Replacing CVSS with DREAD still ignores the need for a discovery method, and relying on CVSS alone-or using it to avoid deeper analysis-would leave undiscovered threats unaddressed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Common Vulnerability Scoring System (CVSS)?
Open an interactive chat with Bash
How does STRIDE compare to CVSS in threat modeling?
Open an interactive chat with Bash
Why is CVSS insufficient on its own for threat modeling?
Open an interactive chat with Bash
What is CVSS and how is it used in cybersecurity?
Open an interactive chat with Bash
What is STRIDE and how does it complement CVSS in threat modeling?
Open an interactive chat with Bash
What makes DREAD different from STRIDE, and why isn't it suitable as a sole threat-modeling approach?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .