Bird
0
0

If a threat scores high on Damage and Exploitability but low on Reproducibility and Discoverability, what should the company prioritize?

hard🚀 Application Q8 of 15
Cybersecurity - Security Architecture and Design
A company uses STRIDE to analyze threats and DREAD to score them. If a threat scores high on Damage and Exploitability but low on Reproducibility and Discoverability, what should the company prioritize?
AFocus on fixing the vulnerability quickly due to high impact
BIgnore the threat because it is hard to reproduce
CDelay action since discoverability is low
DOnly monitor the threat without mitigation
Step-by-Step Solution
Solution:
  1. Step 1: Analyze high Damage and Exploitability

    High damage means serious harm; high exploitability means attackers can easily exploit it.
  2. Step 2: Consider low Reproducibility and Discoverability

    Low reproducibility and discoverability reduce risk but do not eliminate it.
  3. Step 3: Decide priority

    Because impact and ease of attack are high, the company should prioritize fixing the vulnerability quickly.
  4. Final Answer:

    Focus on fixing the vulnerability quickly due to high impact -> Option A
  5. Quick Check:

    High damage + exploitability = urgent fix [OK]
Quick Trick: High damage + exploitability = fix fast [OK]
Common Mistakes:
MISTAKES
  • Ignoring threats with low reproducibility
  • Delaying fixes due to discoverability
  • Only monitoring without action

Want More Practice?

15+ quiz questions · All difficulty levels · Free

Free Signup - Practice All Questions
More Cybersecurity Quizzes