InterviewStack.io LogoInterviewStack.io

Threat Modeling and Attack Surface Analysis Questions

Systematically identifying how a system can be attacked and where its exposure lies. Covers structured methodologies (STRIDE, PASTA, DREAD, OCTAVE, attack trees), enumerating and reducing attack surface, mapping trust boundaries and data flows via DFDs, profiling likely threat actors, and prioritizing identified threats by likelihood and impact during design. Includes applying this methodology to specific architectural substrates (cloud-native and serverless, microservices, ML/AI systems, IoT, CI/CD pipelines, cryptographic subsystems) and operationalizing it as a recurring program (SDLC integration, governance, tooling, KPIs). The proactive 'think like an attacker before you build' discipline: distinct from live penetration testing (the adversarial validation of a built system), from runtime detection/monitoring (recognizing an attack already in progress), and from implementing the resulting security controls (a separate design-and-build discipline).

HardTechnical
33 practiced

Explain how outputs from threat modeling and enterprise risk assessments map to audit evidence required for SOC 2 Type II and ISO 27001 certification. List specific documents, metrics, and implemented controls you would present to auditors to demonstrate compliance and continuous monitoring.

HardTechnical
37 practiced

Propose a probabilistic model that consumes threat intelligence signals such as IOC counts, actor TTP fidelity, exploit availability, and patch presence to estimate the likelihood that a specific vulnerability will be exploited against your environment in the next 30 days. Describe feature selection, weighting strategies, candidate modeling approaches (for example Bayesian update or logistic regression), data sources, and how you would validate and back-test the model.

MediumTechnical
32 practiced

Create a sample risk register entry for a web-facing customer-database breach. Include the following fields: risk-id, description, affected-asset(s), likelihood (1-5), impact (1-5), risk-score, existing-controls, proposed-mitigations, residual-risk, owner, and target-mitigation-date. Explain the values you chose and the rationale behind them.

EasyTechnical
33 practiced

Summarize the Process for Attack Simulation and Threat Analysis (PASTA) methodology: list its stages and briefly describe the objective of each stage. Explain in what situations PASTA is more appropriate than a simpler framework like STRIDE.

EasyTechnical
42 practiced

Compare quantitative and qualitative risk-scoring approaches used in threat modeling. Describe how you would apply a numeric approach (e.g., CVSS or a simplified numeric scale) and a qualitative approach (high/medium/low) to prioritize threats in a small startup with limited security resources, noting advantages and disadvantages of each.

Unlock Full Question Bank

Get access to all Threat Modeling and Attack Surface Analysis interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.