Topic module

Threat Modeling and AI Governance

This topic covers threat modeling frameworks, actor motivation, attack surface, abuse cases, STRIDE, ATT&CK, AI adoption risk, model threats, data exposure, and guardrails.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for CompTIA SecurityX

Treat each SecurityX item as an enterprise security design decision: map requirements, model risk, place controls, engineer constraints, and operationalize evidence.

Core concepts

Concept 1

Threat modeling identifies actors, assets, trust boundaries, attack paths, and controls before or during system design.

Exam cue: Identify actor, asset, trust boundary, abuse case, and control.

Concept 2

AI adoption introduces governance, privacy, model, supply-chain, and excessive-agency risks.

Exam cue: Match framework to modeling objective and system maturity.

Concept 3

Security leaders should choose frameworks and controls that fit architecture, business context, and regulatory obligations.

Exam cue: Govern AI data, permissions, disclosure, and model-specific threats.

Risk pitfalls and guardrails

Threat modeling after deployment only as paperwork.

Guardrail: Avoid answers that ignore governance, overtrust the perimeter, deploy controls without placement logic, skip key management, or automate without guardrails.

Letting an AI assistant access sensitive systems without guardrails.

Guardrail: Avoid answers that ignore governance, overtrust the perimeter, deploy controls without placement logic, skip key management, or automate without guardrails.

Focusing on model output while ignoring training data and plugin risk.

Guardrail: Avoid answers that ignore governance, overtrust the perimeter, deploy controls without placement logic, skip key management, or automate without guardrails.

Memory anchors

STRIDE

STRIDE organizes threats as spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege.

Attack Tree

An attack tree decomposes paths an adversary could use to reach an objective.

Trust Boundary

A trust boundary marks where assumptions and controls change between components.

Abuse Case

An abuse case describes how a system could be misused.

ATT&CK

MITRE ATT&CK organizes adversary tactics and techniques for analysis and coverage.

CAPEC

CAPEC catalogs common attack patterns for threat analysis.

AI Guardrail

AI guardrails constrain model actions, data access, and behavior.

Prompt Injection

Prompt injection attempts to manipulate model behavior through crafted input.

Data Poisoning

Data poisoning corrupts training or reference data to influence behavior.

Model Inversion

Model inversion attempts to infer sensitive training information from model behavior.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

An architect is reviewing a new payment API before coding begins. The team needs to identify where identities, data, and trust assumptions change between the mobile app, gateway, services, and bank. What should the architect create first?

A threat-modeling workshop identifies that a service accepts a caller-supplied account identifier without verifying the caller owns the account. Under STRIDE, which threat is primary?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.