exam questions

Exam 312-96 All Questions

View all questions & answers for the 312-96 exam

Exam 312-96 topic 1 question 16 discussion

Actual exam question from ECCouncil's 312-96
Question #: 16
Topic #: 1
[All 312-96 Questions]

Which of the risk assessment model is used to rate the threats-based risk to the application during threat modeling process?

  • A. DREAD
  • B. SMART
  • C. STRIDE
  • D. RED
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TheRodGpe
Highly Voted 1 year, 2 months ago
Selected Answer: A
"DREAD model is used to rate the various security threats on the application by calculating risks of each threats" From the page 97 of CASE .NET Courseware
upvoted 6 times
...
yawmumma
Highly Voted 1 year, 2 months ago
The DREAD model is commonly used to rate the threats-based risk to an application during the threat modeling process. DREAD stands for: Damage: How bad would an attack be? Reproducibility: How easy is it to reproduce the attack? Exploitability: How much work is it to launch the attack? Affected Users: How many people will be impacted? Discoverability: How easy is it to discover the threat? Each category is usually given a score, and the scores are then used to prioritize threats. So the correct answer is: A. DREAD The other options are not standard risk assessment models used for rating threats in threat modeling: SMART is often used for goal-setting (Specific, Measurable, Achievable, Relevant, Time-bound). STRIDE is another threat modeling methodology that identifies threats but doesn't rate them (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privileges). RED is not a standard risk assessment model in this context. Therefore, DREAD is the model used for rating threats during the threat modeling process.
upvoted 5 times
...
victorfs
Most Recent 8 months ago
Selected Answer: A
The correcto is DREAD!
upvoted 2 times
...
Aalkinani
1 year, 1 month ago
A. DREAD DREAD is an acronym that stands for: Damage Potential: How bad would an attack be? Reproducibility: How easy is it to reproduce the attack? Exploitability: How easy is it to launch the attack? Affected Users: How many users would be impacted? Discoverability: How easy is it to discover the threat? While STRIDE is used to identify threats (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege), DREAD is used to rate and prioritize those threats.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago