Threat Modeling and Attack Surface Analysis Questions

Systematically identifying how a system can be attacked and where its exposure lies. Covers structured methodologies (STRIDE, PASTA, DREAD, OCTAVE, attack trees), enumerating and reducing attack surface, mapping trust boundaries and data flows via DFDs, profiling likely threat actors, and prioritizing identified threats by likelihood and impact during design. Includes applying this methodology to specific architectural substrates (cloud-native and serverless, microservices, ML/AI systems, IoT, CI/CD pipelines, cryptographic subsystems) and operationalizing it as a recurring program (SDLC integration, governance, tooling, KPIs). The proactive 'think like an attacker before you build' discipline: distinct from live penetration testing (the adversarial validation of a built system), from runtime detection/monitoring (recognizing an attack already in progress), and from implementing the resulting security controls (a separate design-and-build discipline).

HardTechnical
40 practiced

Design an approach to automatically generate and score attack trees for common web application goals such as data exfiltration, using static architecture metadata, vulnerability feeds, and threat intelligence. Describe the graph model, algorithms for path enumeration and shortest/cheapest-path identification, scoring heuristics for nodes and edges (ease, likelihood, impact), data storage model, and how results should be presented to engineers for mitigation prioritization.

HardTechnical
43 practiced

For a critical authentication flow, construct an attack tree (describe the high level tree) and explain how you'd assign likelihood and expected cost to each leaf node. Show how to compute expected value for each subtree (probability * impact) and use those values to decide where to place preventive controls versus detection controls.

EasyTechnical
40 practiced

Given the following simplified web application architecture, identify the top six assets, list attack-surface components, and name three high-priority threats.

Architecture:

Client -> CDN -> Load Balancer -> Web Tier -> App Tier -> Database
            |-> S3 Object Storage
            |-> Auth (OIDC)
            |-> CI/CD Pipeline

Explain your reasoning and the initial mitigations you would propose for the high-priority threats.

EasyTechnical
41 practiced

List and explain the step-by-step process you would follow to perform an attack surface analysis for a newly deployed microservice that handles PII. Include the tools you would use, artifacts you would produce, and the cross-functional participants you'd invite for the analysis.

HardTechnical
43 practiced

Given an attack tree that describes all ways to reach 'administrator credentials', what algorithms or approaches would you use to identify a minimal set of nodes to harden to reduce overall risk (e.g., minimum cut, vertex cover, criticality scoring)? Discuss computational complexity and practical heuristics for large trees.

Unlock Full Question Bank

Get access to all 18 Threat Modeling and Attack Surface Analysis interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.