Security · Threat Modeling
How would you answer an interview scenario involving threat modeling?
In an interview, I would first define threat modeling and the problem it solves, then explain how I would diagram data flows and trust boundaries, identify assets and attackers, enumerate threats, prioritize by impact and likelihood, assign mitigations, and revisit the model when architecture or exposure changes. I would also call out the main failure mode: performing threat modeling once as a compliance document and never updating it causes the model to diverge from the real system. Finally, I would describe how I would test, monitor, and safely roll back or recover the solution.