ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While decomposing a new public-facing API, the team subscribes to a trusted STIX/TAXII feed that reports a surge in token-spraying attacks against similar services. Which action best leverages this intelligence within the threat-modeling activity?
Correlate the reported campaign techniques with the API's entry points and update STRIDE data-flow diagrams to include credential-stuffing threats.
Abandon the current authentication design and mandate client-side certificates to eliminate credential attacks entirely.
Defer use of the feed until the penetration testing phase when live exploits can be validated.
Forward the indicators to network operations so they can filter out any false positives before design work proceeds.
Threat intelligence is most useful during threat modeling when it is mapped to specific components and trust boundaries so that realistic attacker capabilities can be incorporated into diagrams such as STRIDE data-flow models. Doing so helps identify where additional controls (e.g., rate limiting, step-up authentication) are needed and lets the team prioritize mitigations based on documented adversary techniques. Simply forwarding the feed to operations, postponing analysis until penetration testing, or completely redesigning authentication without further analysis fails to integrate the intelligence with the architectural context and does not fully support risk-based design decisions.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is STIX/TAXII and why is it relevant to API threat modeling?
Open an interactive chat with Bash
What is a STRIDE data-flow diagram and how is it used in threat modeling?
Open an interactive chat with Bash
What is a token-spraying attack, and how does it relate to API security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .