Based on an internal assessment, a vulnerability management team wants to proactively identify risks to the infrastructure prior to production deployments. Which of the following best supports this approach?
Threat modelingis aproactiveapproach used toidentify, analyze, and mitigate potential threatsbefore they impact production systems. It is especially useful in early development stages to anticipate vulnerabilities and attack paths.
Option B (Penetration testing)is areactive measureperformed on deployed systems, rather than prior to production.
Option C (Bug bounty)programs incentivize external researchers but do not proactively model risksbefore deployment.
Option D (SDLC training)improves security awareness but does notactively assess risks.
Thus,A (Threat modeling) is the best choice, as it enablesearly identification and mitigation of security risks.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit