CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security
Meridian Pay's team follows a secure software development life cycle. During the design phase, it systematically identifies assets, entry points, possible attackers and likely attack paths so that countermeasures can be planned before coding begins. Which activity is being performed, and what distinguishes it from penetration testing?
The activity is threat modelling, a proactive design-stage exercise that identifies assets, entry points, attackers and attack paths so controls are planned before coding. Penetration testing differs because it actively probes a built or running system to find and exploit real weaknesses.
- AThreat modelling, which is done proactively at design time, whereas penetration testing probes a built system for exploitable weaknessesCorrect
- BPenetration testing, which is done at design time, whereas threat modelling is done after deployment
- CCode signing, which verifies publisher identity, whereas penetration testing encrypts the code
- DPatch management, which applies vendor updates, whereas penetration testing removes the need for design review
Explanation
Identifying assets, entry points, adversaries and attack paths during design is threat modelling, a proactive step that shapes controls before code exists. Penetration testing is performed on a built or running system to find exploitable weaknesses. The other options misdescribe the timing or purpose of the activities.
Did you get it right without looking?
One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.
More Softwares and Software Security questions
- A program copies more data into a fixed-size memory area than it can hold, overwriting adjacent memory and allowing an attacker to run injec…
- Under the Information Technology Act, 2000, a software developer in Pune deliberately inserts a hidden routine into a client's accounting so…
- Which activity is characteristic of a secure SDLC, as distinct from an ordinary SDLC?
- A company secretary is told that a software team has finished writing code for a payroll module and now plans to run unit, integration and s…
- A developer in Hyderabad releases a tool under GPL. A Chennai firm modifies it, bundles it into a product and distributes the product to cus…
- Under the Indian Copyright Act, 1957, a computer programme is protected as which type of work?