Study. uk . com
  1. Home
  2. All questions
  3. Question 207

CompTIA Security+ study material · question 207 of 611

Why is threat modelling most valuable during design rather than after implementation?

  1. Because developers are less busy at that stage
  2. Because the fixes it suggests are architectural and become expensive once code exists
  3. Because code cannot be reviewed until it is complete
  4. Because threat intelligence is more accurate early
Show the answer

Answer: B. Because the fixes it suggests are architectural and become expensive once code exists

A design-level finding usually means changing structure, which is far cheaper before the structure is built.

Source: OWASP Threat Modeling Cheat Sheet (OWASP) — OWASP Threat Modeling Cheat Sheet › Introduction

Challenge yourself on this topic → Study as cards