Security Architecture and Engineering Question #65

A healthcare organization is migrating patient records to the cloud. Which of the following sequences of actions represents the most appropriate approach for a threat modeling exercise?

A. Identifying threats, creating a threat model, identifying assets, assessing associated risks, prioritizing risk mitigation measures.
B. Identifying assets, creating a threat model, identifying threats, assessing associated risks, prioritizing risk mitigation
C. Creating a threat model, identifying assets, identifying threats, assessing associated risks, prioritizing risk mitigation measures.
D. Identifying assets, identifying threats, creating a threat model, prioritizing risk mitigation measures, assessing associated risks.
Domain Concept: Security Architecture and Engineering

This scenario evaluates management-level decision making in Security Architecture and Engineering. In CISSP exam scenarios, evaluate answers through executive governance, risk assessment, life safety, and due diligence before implementing technical controls.

💡 View the Answer & Detailed Explanation

The correct answer to this scenario-based question requires an understanding of the CISSP Managerial Mindset. Register to view our in-depth explanation and access 1100+ adaptive questions completely free.

Fuel the Mission ☕

Keep the vault updated and the servers running.

$
Secure Payment via PayPal

Verified Excellence

Spread the Word

If you like us, share us with your peers.

Scroll to Top