- Home
- All questions
- Question 207
CompTIA Security+ study material · question 207 of 611
Why is threat modelling most valuable during design rather than after implementation?
Show the answer
Answer: B. Because the fixes it suggests are architectural and become expensive once code exists
A design-level finding usually means changing structure, which is far cheaper before the structure is built.
Source: OWASP Threat Modeling Cheat Sheet (OWASP) — OWASP Threat Modeling Cheat Sheet › Introduction