Threat Modeling and Attack Surface Analysis Questions

Systematically identifying how a system can be attacked and where its exposure lies. Covers structured methodologies (STRIDE, PASTA, DREAD, OCTAVE, attack trees), enumerating and reducing attack surface, mapping trust boundaries and data flows via DFDs, profiling likely threat actors, and prioritizing identified threats by likelihood and impact during design. Includes applying this methodology to specific architectural substrates (cloud-native and serverless, microservices, ML/AI systems, IoT, CI/CD pipelines, cryptographic subsystems) and operationalizing it as a recurring program (SDLC integration, governance, tooling, KPIs). The proactive 'think like an attacker before you build' discipline: distinct from live penetration testing (the adversarial validation of a built system), from runtime detection/monitoring (recognizing an attack already in progress), and from implementing the resulting security controls (a separate design-and-build discipline).

HardTechnical
34 practiced

Given this architecture description, identify hidden trust boundary misconfigurations and propose design changes:

  • Mobile app (public) communicates with an API Gateway (public L7) → routes to API service running in the same VPC as the database
  • API service connects directly to Database on port 5432 with a single shared DB credential
  • Admin UI deployed in the same cluster as the API uses the same DB credentials and exposes an admin route on a public load balancer
  • CI system can run arbitrary scripts that have network access to the cluster

List at least five issues, explain the associated risks, and propose fixes prioritized by impact and effort.

MediumTechnical
34 practiced

Walk through a threat modeling exercise for a new cloud-native microservice that accepts file uploads and stores them in object storage. Use an explicit framework (e.g., STRIDE) to identify assets, actors, threats, attack paths, and mitigations. List the artifacts you'd produce (data flow diagram, threat list, prioritized mitigations) and one example detection control for a critical threat.

HardTechnical
32 practiced

Perform a STRIDE analysis for a typical CI/CD pipeline composed of a source repository, CI runners/build agents, artifact registries, deployment service, and production environment. Identify specific attack vectors (compromised credentials, dependency poisoning, malicious build steps), propose mitigations (artifact signing, least-privilege runners, ephemeral agents), and recommend detection mechanisms.

MediumTechnical
46 practiced

Write a Python script or clear pseudocode that reads a CSV file named 'vulnerabilities.csv' with columns: id, cvss (0.0-10.0), asset_criticality (1-5). Compute a normalized risk score defined as risk = (cvss/10.0) * (asset_criticality/5.0). Output the top 10 vulnerabilities sorted by risk descending, printing id and score. The solution should handle large files without loading everything into memory at once.

MediumSystem Design
43 practiced

Draw or describe a Data Flow Diagram (textual description acceptable) for a microservices-based payment system composed of: frontend, API gateway, payment service, order service, user service, third-party payment processor, and database. Identify trust boundaries and list three components that should be considered privileged or high-value targets, explaining why.

Unlock Full Question Bank

Get access to all 20 Threat Modeling and Attack Surface Analysis interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.