🔍

CompTIA SecurityX (CAS-005) CAS-005 — Question 190

Topic 1 · Question 190 of 393

Topic 1 · Question 190

A company wants to perform threat modeling on an internally developed, business-critical application. The Chief Information Security Officer (CISO) is most concerned that the application should maintain 99.999% availability and authorized users should only be able to gain access to data they are explicitly authorized to view. Which of the following threat-modeling frameworks directly addresses the CISO’s concerns about this system?

View community discussion →