Which of the following is a STRIDE threat category?

Get ready for your WGU ITEC2034 D385 Software Security and Testing Test. Study with multiple choice questions that include hints and explanations. Boost your confidence for your exam day!

Multiple Choice

Which of the following is a STRIDE threat category?

Explanation:
STRIDE is a framework that classifies threats by the way an attacker abuses a system, listing six categories of threats. Spoofing is one of these categories and refers to pretending to be someone or something else to gain unauthorized access or privileges. This is a direct STRIDE threat category—the attacker masquerades identity to breach security. The other options describe security goals rather than a STRIDE threat category. Confidentiality, Integrity, and Availability are the properties we want to protect (keeping data secret, keeping data correct, and keeping services running). In STRIDE terms, those concerns map to Information Disclosure (confidentiality), Tampering (integrity), and Denial of Service (availability), but they themselves aren’t the STRIDE categories.

STRIDE is a framework that classifies threats by the way an attacker abuses a system, listing six categories of threats. Spoofing is one of these categories and refers to pretending to be someone or something else to gain unauthorized access or privileges. This is a direct STRIDE threat category—the attacker masquerades identity to breach security.

The other options describe security goals rather than a STRIDE threat category. Confidentiality, Integrity, and Availability are the properties we want to protect (keeping data secret, keeping data correct, and keeping services running). In STRIDE terms, those concerns map to Information Disclosure (confidentiality), Tampering (integrity), and Denial of Service (availability), but they themselves aren’t the STRIDE categories.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy