Threat Modeling and Attack Surface Analysis Questions

Systematically identifying how a system can be attacked and where its exposure lies. Covers structured methodologies (STRIDE, PASTA, DREAD, OCTAVE, attack trees), enumerating and reducing attack surface, mapping trust boundaries and data flows via DFDs, profiling likely threat actors, and prioritizing identified threats by likelihood and impact during design. Includes applying this methodology to specific architectural substrates (cloud-native and serverless, microservices, ML/AI systems, IoT, CI/CD pipelines, cryptographic subsystems) and operationalizing it as a recurring program (SDLC integration, governance, tooling, KPIs). The proactive 'think like an attacker before you build' discipline: distinct from live penetration testing (the adversarial validation of a built system), from runtime detection/monitoring (recognizing an attack already in progress), and from implementing the resulting security controls (a separate design-and-build discipline).

HardSystem Design
46 practiced

Design a threat model for a serverless data processing pipeline (API Gateway -> Lambda -> Kinesis -> analytics). Identify threats including event injection, function impersonation, excessive privileges, insecure dependencies, and cold-start related timing risks. Recommend mitigations across IAM, VPC placement, input validation, dependency management, observability, and secure deployment patterns.

HardTechnical
65 practiced

Perform a detailed threat model for a multi-tenant cloud data warehouse used by regulated customers. Focus on tenant isolation, side-channel risks, data exfiltration, privileged access, query logs, and metadata leakage. Recommend architectural mitigations (encryption per tenant, query sandboxing, workload isolation) and controls to demonstrate isolation to auditors.

HardSystem Design
39 practiced

For a multi-region active-active microservices platform using service mesh and automated CI/CD with cross-region data replication, produce a threat model identifying high-impact threats (misconfiguration, pipeline compromises, secrets leakage, replication divergence) and propose architecture and operational mitigations to preserve availability and security during region failures or CI/CD rollback scenarios.

EasyTechnical
46 practiced

You are onboarding a new SaaS tenant: describe how you would enumerate assets and the attack surface for their single-tenant web app deployed in AWS. Include cloud resources (compute, storage, IAM), developers' workstations, CI/CD pipelines, third-party integrations, mobile clients, and customers' browsers in your enumeration and explain how the attack surface expands with each asset class.

MediumTechnical
34 practiced

How does threat modeling change for serverless and cloud-native architectures compared to traditional VM-based designs? Identify unique attack surfaces (e.g., functions, event sources, IAM roles, managed services), and list recommended mitigation patterns and observability practices.

Unlock Full Question Bank

Get access to all 8 Threat Modeling and Attack Surface Analysis interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.