QuestionQ43

Vulnerability Management

Based on an internal assessment, a vulnerability management team aims to proactively identify infrastructure risks before production deployments. Which of the following best supports this approach?

Explanation

Threat modeling systematically evaluates a system’s design, attack surface, potential attackers, and threats so that risks can be identified and addressed before production deployment. NIST describes threat modeling as a form of risk assessment and notes that it can identify design-level security issues.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!