Threat Modeling and Attack Surface Analysis Questions

Systematically identifying how a system can be attacked and where its exposure lies. Covers structured methodologies (STRIDE, PASTA, DREAD, OCTAVE, attack trees), enumerating and reducing attack surface, mapping trust boundaries and data flows via DFDs, profiling likely threat actors, and prioritizing identified threats by likelihood and impact during design. Includes applying this methodology to specific architectural substrates (cloud-native and serverless, microservices, ML/AI systems, IoT, CI/CD pipelines, cryptographic subsystems) and operationalizing it as a recurring program (SDLC integration, governance, tooling, KPIs). The proactive 'think like an attacker before you build' discipline: distinct from live penetration testing (the adversarial validation of a built system), from runtime detection/monitoring (recognizing an attack already in progress), and from implementing the resulting security controls (a separate design-and-build discipline).

EasyTechnical
33 practiced

Explain the STRIDE threat modeling categories (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege). For each category, provide a concise example vulnerability or attack path in the context of a web-based e-commerce application (authentication, payments, product catalog) and explain why it maps to that STRIDE category.

HardSystem Design
39 practiced

For a multi-region active-active microservices platform using service mesh and automated CI/CD with cross-region data replication, produce a threat model identifying high-impact threats (misconfiguration, pipeline compromises, secrets leakage, replication divergence) and propose architecture and operational mitigations to preserve availability and security during region failures or CI/CD rollback scenarios.

HardTechnical
35 practiced

You discover a high-severity vulnerability that can be remediated only by disabling a widely used feature for 48 hours, which would reduce expected revenue by approximately 10%. As an SRE lead, how do you present the options to executive stakeholders, recommend a course of action, set measurable metrics to evaluate risk reduction, and plan communications and rollback? Explain how you would make the tradeoff clear and obtain buy-in.

EasyTechnical
33 practiced

Summarize the Process for Attack Simulation and Threat Analysis (PASTA) methodology: list its stages and briefly describe the objective of each stage. Explain in what situations PASTA is more appropriate than a simpler framework like STRIDE.

MediumTechnical
46 practiced

Perform a threat model for a flow where an external partner uploads files via SFTP to a staging bucket, an Airflow DAG triggers a Spark job in Kubernetes to transform data, and the results populate a multi-tenant analytics database. Identify top attack surfaces, mitigations for supply-chain and insider threats, and detection controls to add at ingestion, processing, and serving layers.

Unlock Full Question Bank

Get access to all Threat Modeling and Attack Surface Analysis interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.