ISTQB · Topic 3 of 15
Threat Modeling & Risk Assessment
STRIDE. PASTA. Attack trees. Tying threats to test cases.
6 lessons180 questions
What this topic covers
- 01Abuse Cases and Attack Trees for Threat Modeling300m
- 02CVE, CVSS, and Context-Specific Security Testing480m
- 03Hardcoded Credentials, IAM Testing, and Injection in Mobile Apps480m
- 04PASTA Threat Modeling and NVD for Risk-Based Security Testing600m
- 05SAST, SCA, SBOM, and STRIDE for Security Risk Assessment480m
- 06Threat Modeling-Based Test Design and Risk Prioritization600m
Other topics in CT-STE — Security Test Engineer
Introduction to Security Test Engineering6 lessonsFundamentals of Security Testing4 lessonsSecurity Test Design5 lessonsApplication Security Testing6 lessonsSpecific Security Test Topics8 lessonsSecurity Testing Tools7 lessonsSecurity Test Automation & CI/CD Integration6 lessonsSecurity Test Implementation and Execution7 lessonsSecurity Test Analysis and Reporting4 lessonsInfrastructure & Network Testing6 lessonsCryptography & Data Protection Testing6 lessonsSecurity Testing as Part of an ISMS4 lessonsSecurity Test Strategy and Planning5 lessonsStandards, Regulations, and Compliance4 lessons