Skip to content
Tech Interview Prep home
Technical interview guide

Threat Modeling & Risk Assessment

Systematically identifying what could go wrong, before it does — frameworks like STRIDE and risk scoring.

Read
32 min
Practice MCQs
25
Interview QA
25
Edition
v4
Editorial status
Reviewed
Relevant for
Security Architect

Scope: NIST SP 800-30 Rev. 1; NIST CSF 2.0; NIST SP 1303; NIST SP 800-154 initial public draft status noted; ATT&CK and CAPEC accessed 2026-08-31.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Lead a threat-modeling session for a new system.

QA-2

Threat-model a multi-tenant SaaS application.

QA-3

Build a data-centric threat model for sensitive information.

QA-4

Write high-quality threat scenarios from a system diagram.

QA-5

Assess likelihood when evidence is sparse.

QA-6

Assess business and mission impact for a technical scenario.

QA-7

Prioritize a portfolio of threat-model findings.

QA-8

Choose controls for a prioritized threat scenario.

QA-9

Model authentication and authorization threats for an API.

QA-10

Threat-model a CI/CD and software supply chain.

QA-11

Threat-model a third-party SaaS dependency.

QA-12

Model insider and authorized-feature abuse.

QA-13

Threat-model reliability, safety, and non-adversarial failures.

QA-14

Handle risk acceptance responsibly.

QA-15

Translate threat-model findings into an engineering roadmap.

QA-16

Validate that a mitigation actually reduced risk.

QA-17

Maintain threat models as systems evolve.

QA-18

Use ATT&CK and CAPEC appropriately in threat modeling.

QA-19

Integrate threat modeling into a secure SDLC.

QA-20

Automate parts of threat modeling without automating risk ownership.

QA-21

Design threat-modeling program metrics that resist gaming.

QA-22

Threat-model an AI-enabled product feature.

QA-23

Respond when an incident reveals an unmodeled threat path.

QA-24

Review a threat model for quality and completeness.

QA-25

Lead an end-to-end risk assessment for a major architecture decision.