Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

QUESTION 6 A disadvantage of an informal threat management apprenticeship is: a.

ID: 3712736 • Letter: Q

Question

QUESTION 6 A disadvantage of an informal threat management apprenticeship is: a. It costs less b. The mentor is very knowledgable c. It is scalable d. None of the above 5.00000 points

QUESTION 7 An experimental approach that brings two systems groups together for threat modeling is called a: a. Fulsome review b. Intersystem review c. STRIDE group d. Postmortem review board 5.00000 points

QUESTION 8 Which of the following is not a phase in the cyber kill chain? a. Reconnaissance b. Weaponization c. Expiration d. Installation 5.00000 points

QUESTION 9 Which of the following is considered a threat to threat modeling? a. Enumerating all possible assumptions b. Kill chain c. Intersystem reviews d. B and C, but not A 5.00000 points

QUESTION 10 Which is a key aspect of aligning threat modeling with finding flow? Setting clear goals Obtaining direct and immediate feedback Finding a balance between ability and challenge All of the above

Explanation / Answer

Please follow the below answer.

QUESTION 6 . A disadvantage of an informal threat management apprenticeship is:

Answer: d) None of the above.

Cause:

Disadvantages of an informal threat management apprenticeship are such that the low performance, costly to implement , chances to be failed in single point, impossible to scale for large environment , seller confinement.

QUESTION 7. An experimental approach that brings two systems groups together for threat modeling is called

Answer: c. STRIDE group

Cause :

Stride group meetings and reviews is a complete team communication solution to take a business decision in a structured and experimental way at a single place combining two or more system groups versions having all members together for threat modeling.

QUESTION 8. Which of the following is not a phase in the cyber kill chain?

Answer: c. Expiration

Cause: Phases of cyber kill chain are –Find, Fix, Track, Target, Engage, Assess.

QUESTION 9. Which of the following is considered a threat to threat modeling?

Answer: d. B and C, but not A

Cause: kill chain is the structured process to tackle all the threats by some phases like Find, Fix, Track, Target, Engage, Assess, whereas Intersystem reviews are the development management , test and program management pact for the system consisting with security experts to tackle all the threats.

QUESTION 10. Which is a key aspect of aligning threat modeling with finding flow?

Answer: d) All of these.

Setting clear goals ,Obtaining direct and immediate feedback ,Finding a balance between ability and challenge are the three key aspect of aligning threat modeling with finding flows by following the process reports, analyzing feedback and implementing new features as challenge.