QUESTION 6 A disadvantage of an informal threat management apprenticeship is: a.
ID: 3712736 • Letter: Q
Question
QUESTION 6 A disadvantage of an informal threat management apprenticeship is: a. It costs less b. The mentor is very knowledgable c. It is scalable d. None of the above 5.00000 points
QUESTION 7 An experimental approach that brings two systems groups together for threat modeling is called a: a. Fulsome review b. Intersystem review c. STRIDE group d. Postmortem review board 5.00000 points
QUESTION 8 Which of the following is not a phase in the cyber kill chain? a. Reconnaissance b. Weaponization c. Expiration d. Installation 5.00000 points
QUESTION 9 Which of the following is considered a threat to threat modeling? a. Enumerating all possible assumptions b. Kill chain c. Intersystem reviews d. B and C, but not A 5.00000 points
QUESTION 10 Which is a key aspect of aligning threat modeling with finding flow? Setting clear goals Obtaining direct and immediate feedback Finding a balance between ability and challenge All of the above
Explanation / Answer
Please follow the below answer.
QUESTION 6 . A disadvantage of an informal threat management apprenticeship is:
Answer: d) None of the above.
Cause:
Disadvantages of an informal threat management apprenticeship are such that the low performance, costly to implement , chances to be failed in single point, impossible to scale for large environment , seller confinement.
QUESTION 7. An experimental approach that brings two systems groups together for threat modeling is called
Answer: c. STRIDE group
Cause :
Stride group meetings and reviews is a complete team communication solution to take a business decision in a structured and experimental way at a single place combining two or more system groups versions having all members together for threat modeling.
QUESTION 8. Which of the following is not a phase in the cyber kill chain?
Answer: c. Expiration
Cause: Phases of cyber kill chain are –Find, Fix, Track, Target, Engage, Assess.
QUESTION 9. Which of the following is considered a threat to threat modeling?
Answer: d. B and C, but not A
Cause: kill chain is the structured process to tackle all the threats by some phases like Find, Fix, Track, Target, Engage, Assess, whereas Intersystem reviews are the development management , test and program management pact for the system consisting with security experts to tackle all the threats.
QUESTION 10. Which is a key aspect of aligning threat modeling with finding flow?
Answer: d) All of these.
Setting clear goals ,Obtaining direct and immediate feedback ,Finding a balance between ability and challenge are the three key aspect of aligning threat modeling with finding flows by following the process reports, analyzing feedback and implementing new features as challenge.