Threat Modeling and Attack Surface Analysis Questions

Systematically identifying how a system can be attacked and where its exposure lies. Covers structured methodologies (STRIDE, PASTA, DREAD, OCTAVE, attack trees), enumerating and reducing attack surface, mapping trust boundaries and data flows via DFDs, profiling likely threat actors, and prioritizing identified threats by likelihood and impact during design. Includes applying this methodology to specific architectural substrates (cloud-native and serverless, microservices, ML/AI systems, IoT, CI/CD pipelines, cryptographic subsystems) and operationalizing it as a recurring program (SDLC integration, governance, tooling, KPIs). The proactive 'think like an attacker before you build' discipline: distinct from live penetration testing (the adversarial validation of a built system), from runtime detection/monitoring (recognizing an attack already in progress), and from implementing the resulting security controls (a separate design-and-build discipline).

HardTechnical
36 practiced

During an architecture review you discover several chained weaknesses that together enable privilege escalation: an exposed admin endpoint (high exposure), a weak auth policy (medium), and an outdated library with a remote code execution bug (low). Discuss how you would prioritize mitigations, propose immediate and medium-term actions, and explain what residual risk (if any) you would accept and why.

MediumSystem Design
35 practiced

Walk me through using the PASTA threat modeling methodology for a new public REST API that stores user profiles. Outline the seven PASTA stages, identify who should be involved in each stage (roles), list artifacts you would produce (e.g., DFDs, attack trees), and explain how PASTA outputs feed into risk scoring and controls selection.

HardSystem Design
39 practiced

Design a prioritized remediation roadmap for a multi-cloud organization with a limited number of security engineers. Include decision criteria for prioritization (risk reduction per effort), use of compensating controls, acceptance and escalation processes, realistic timelines, and communication strategies for engineering teams and executives.

MediumSystem Design
39 practiced

Design a prioritized 90-day attack surface reduction plan for a mid-size company's AWS environment covering network exposure, IAM policies, unused services, container registries, and third-party integrations. Provide milestones, measurable goals, and quick wins that reduce exposure while remaining operationally feasible.

MediumTechnical
34 practiced

List and explain essential evaluation criteria when selecting a commercial or open-source threat modeling tool for enterprise use (e.g., collaboration, integration, artifact traceability, automation, compliance mapping). Which criteria would you prioritize for a global bank and why?

Unlock Full Question Bank

Get access to all Threat Modeling and Attack Surface Analysis interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.