200-201 exam dumps

200-201 practice question 35 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 35

Select 4

As a cybersecurity analyst, you are tasked with conducting threat modeling for a new web application that your organization is deploying. During the process, you identify potential attackers, vulnerabilities in the system, and the ways these vulnerabilities could be exploited. Which of the following are key steps you should take to ensure a comprehensive threat modeling process?

  1. A

    Identify assets that need protection and their value to the organization.

  2. B

    Map out potential attack vectors based on the application’s architecture.

  3. C

    Focus solely on known threats from previous incidents within the organization.

  4. D

    Define potential threat actors and their motivations.

  5. E

    Assign a mitigation strategy to each identified threat.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

Threat modeling is a structured approach to identifying and addressing potential threats to a system. Key steps include identifying valuable assets, mapping attack vectors, defining potential threat actors, and assigning mitigation strategies to identified risks. Focusing solely on known threats is insufficient, as it neglects new or evolving threats that may impact the system.

  • A. Correct.

    Correct: Identifying assets and understanding their value is a critical step in threat modeling, as it helps prioritize threats based on impact.

  • B. Correct.

    Correct: Mapping out attack vectors enables you to visualize how attackers might exploit vulnerabilities in the system.

  • C. Incorrect.

    Incorrect: Focusing only on known threats limits the scope of the analysis and ignores emerging or unknown threats.

  • D. Correct.

    Correct: Defining threat actors and their motivations helps you understand who might target the system and why, allowing for more tailored defenses.

  • E. Correct.

    Correct: Assigning mitigation strategies to threats ensures that risks identified during the modeling process are addressed effectively.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam