Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security

Meridian Pay's team follows a secure software development life cycle. During the design phase, it systematically identifies assets, entry points, possible attackers and likely attack paths so that countermeasures can be planned before coding begins. Which activity is being performed, and what distinguishes it from penetration testing?

The activity is threat modelling, a proactive design-stage exercise that identifies assets, entry points, attackers and attack paths so controls are planned before coding. Penetration testing differs because it actively probes a built or running system to find and exploit real weaknesses.

  1. AThreat modelling, which is done proactively at design time, whereas penetration testing probes a built system for exploitable weaknessesCorrect
  2. BPenetration testing, which is done at design time, whereas threat modelling is done after deployment
  3. CCode signing, which verifies publisher identity, whereas penetration testing encrypts the code
  4. DPatch management, which applies vendor updates, whereas penetration testing removes the need for design review

Explanation

Identifying assets, entry points, adversaries and attack paths during design is threat modelling, a proactive step that shapes controls before code exists. Penetration testing is performed on a built or running system to find exploitable weaknesses. The other options misdescribe the timing or purpose of the activities.

Did you get it right without looking?

One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.

More Softwares and Software Security questions