Security · Threat Modeling
How would you answer an interview scenario involving security risk assessment?
In an interview, I would first define security risk assessment and the problem it solves, then explain how I would use consistent criteria, include asset value and exposure, document assumptions, distinguish inherent from residual risk, assign owners, and review accepted risks when conditions change. I would also call out the main failure mode: using vulnerability severity alone without exploitability or business impact can cause teams to fix low-value findings while higher-risk scenarios remain open. Finally, I would describe how I would test, monitor, and safely roll back or recover the solution.