712-50 exam dumps

712-50 practice question 356 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 356

Single answerThreat modeling principles, methodologies, techniques and simulations

A global retail company is rebuilding its e-commerce platform as a set of cloud-hosted microservices that process payment card data, customer profiles, and loyalty rewards. The CISO wants a threat modeling approach that can be repeated across development teams, helps prioritize security investments before production release, and can be validated through realistic exercises. Time is limited, so the organization cannot perform deep code review on every service before launch. Which approach should the CISO choose FIRST to achieve the best risk-informed outcome?

  1. A

    Run a STRIDE-based threat modeling workshop using data flow diagrams for the highest-risk services and trust boundaries, then validate critical abuse cases through tabletop and attack simulation exercises

  2. B

    Delay deployment until every microservice has completed full manual source code review, because threat modeling is less reliable than code inspection

  3. C

    Use only vulnerability scanning after deployment, since cloud-native services change too quickly for structured threat modeling to remain useful

  4. D

    Adopt a single enterprise risk register entry for the entire platform and defer service-level analysis until after the first security incident

Show answer and explanation

Correct answer: A

Explanation

For a CCISO-level decision, the key is selecting an approach that is scalable, risk-based, and actionable across business and technology teams. A structured threat modeling methodology such as STRIDE, supported by data flow diagrams and trust boundary analysis, is widely recognized as an effective way to identify design and architecture risks early. This aligns with secure-by-design principles promoted by organizations such as NIST and OWASP. NIST guidance on risk management and secure software development emphasizes identifying threats early, prioritizing based on impact and likelihood, and validating assumptions through testing and exercises. OWASP Threat Modeling guidance similarly recommends decomposing systems, identifying threats, and defining mitigations iteratively. Simulations such as tabletop exercises and attack-path validation are useful because they test whether modeled threats are realistic and whether controls and response processes are adequate. For a CISO, the most effective first step is not exhaustive review of everything, but a repeatable method focused on the highest-risk services and business-critical data flows.

  • A. Correct.

    This is the best answer because it combines a structured methodology with practical validation. STRIDE is a well-established threat modeling method for identifying threats across spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. Using data flow diagrams helps teams identify assets, processes, data stores, external entities, and trust boundaries in a consistent, repeatable way across microservices. Focusing first on the highest-risk services is appropriate when time is limited and aligns with risk-based prioritization expected at the executive level. Validating high-priority abuse cases through tabletop exercises and attack simulations helps confirm assumptions, test response readiness, and improve investment decisions before production release.

  • B. Incorrect.

    This is incorrect because full manual source code review of every microservice is often impractical under real delivery timelines and does not replace threat modeling. Code review is valuable for finding implementation flaws, but threat modeling is intended to identify design-level weaknesses, misuse cases, architectural trust boundary issues, and missing controls earlier in the lifecycle. A CISO should prioritize scalable, risk-based activities rather than impose a gate that may delay business objectives without proportionate risk reduction.

  • C. Incorrect.

    This is incorrect because post-deployment vulnerability scanning alone is reactive and insufficient. Vulnerability scanning can identify known weaknesses and configuration issues, but it does not systematically uncover architectural threats, business logic abuse, privilege boundary problems, or attacker paths across services. The misconception here is treating scanning as a substitute for threat modeling. In practice, scanning should complement, not replace, design-stage analysis.

  • D. Incorrect.

    This is incorrect because a single high-level risk register entry is too coarse for an environment composed of multiple microservices handling different data types and trust relationships. Deferring service-level analysis until after an incident is contrary to proactive security leadership. Threat modeling is most effective when used before release to influence design, control selection, and compensating safeguards. This option reflects a governance-only approach without sufficient operational depth.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam