Threat modeling: Which periodic assessment activity fits this proactive, pre-deployment structuring need?
Proactively mapping attackers, assets and attack paths before go-live is threat modeling.
The question
Before an AI-driven payment system goes live, a security team wants to systematically enumerate who might attack it, which assets are at stake and the paths an attacker could take, so controls can be designed proactively rather than discovered after an incident. Which periodic assessment activity fits this proactive, pre-deployment structuring need?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Red teaming, which has specialists actively attempt to break the running system so real weaknesses are demonstrated under attack.Almost right but mistimed: red teaming exercises a live system rather than pre-emptively mapping the attack surface as a design input.
- A compliance audit, which checks the deployed system against documented policies, controls and regulatory requirements for conformity.Almost right but off-purpose: an audit verifies conformity to requirements, not the proactive enumeration of adversaries and attack paths.
- Threat modeling, which systematically enumerates adversaries, assets and attack paths so controls can be designed before deployment. ✓Correct: threat modeling is the structured, proactive practice of mapping attackers, assets and paths to inform controls ahead of go-live.
- Load testing, which measures how the system behaves under heavy concurrent demand to confirm it meets performance and scaling targets.Plausible but wrong: load testing assesses performance under demand, unrelated to identifying attackers, assets and attack paths.
The trap
Confusing threat modeling (planning the attack surface) with red teaming (attacking the live system). How to remember it
Proactively mapping attackers, assets and attack paths before go-live is threat modeling.
How many of these would you get right?
One of 499 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Deployment and Use questions
- An AI impact assessment: Which activity should the lead perform? →
- Whether sufficient: When evaluating the context of an AI use case before deployment, which of the following is →
- Full control to tailor the model to its unique data: Which opportunity best justifies taking on that burden? →
- All 135 Understanding How to Govern AI Deployment and Use questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use ·
Every answer, right and wrong, comes with its own explanation.