Threat Modelling: Assets, Adversaries and Trust Boundaries · seed 1 · A4, ink-friendly. The answer key prints on its own page for grown-ups.

Name it before you defend it

Computing · Networks & Security · ages 21-22
Name ______________________   Date ____________
  1. In the school example, which asset hurts most if lost?

    • The lunch menu
    • Pupil records
    • The screensaver
  2. What must you name before choosing defences?

    • Assets, adversaries, and boundary crossings
    • Favorite colors and mascots
    • Server room paint
  3. Every defence should answer one named threat.

    Circle one:   True   False

  4. Where do you mark a trust boundary?

    • Where the office carpet changes color
    • Where data leaves your control for the wider net
    • Where lunch starts
  5. A message asks for your password on a copied page. Who is the adversary?

    • The school printer running low
    • Phishers tricking you into handing over details
    • A lost delivery van
  6. How do you rank two assets?

    • By what each loss would cost
    • By alphabetical order
    • By file size alone
  7. Which defence answers phishers in the school example?

    • Reply with your password quickly
    • Forward the mail to everyone
    • Check the sender and avoid login links from mail
  8. A pricey filter stops no named threat. What do you do?

    • Buy a second filter for luck
    • Rename the filter
    • Move the effort to a crossing that needs it
LightMySky · lightmysky.comW1-mt_VRXTkrNFvx-s1

Answer key

For grown-ups. Fold this page away before handing over the rest.

Name it before you defend it W1-mt_VRXTkrNFvx-s1

  1. Pupil records · Pupil records cost far more than menus or screensavers when lost.
  2. Assets, adversaries, and boundary crossings · The three names aim every later defence at a real risk.
  3. True · Matching keeps effort on real risks instead of vague worries.
  4. Where data leaves your control for the wider net · Crossings out of your control are where protection matters most.
  5. Phishers tricking you into handing over details · Fake pages harvesting logins are the phisher method.
  6. By what each loss would cost · Loss cost decides where protection effort lands first.
  7. Check the sender and avoid login links from mail · Sender checks plus no clicked login links starve the fake page.
  8. Move the effort to a crossing that needs it · Unmatched effort should move to a crossing with a real adversary.
Worksheet · LightMySky