問題文
What does a threat model of an application produce that a vulnerability scan of the same application does not?
選択肢
- A statement of which ports the host exposes and which services answer on them at the time of the run.
- A statement of which packages the build imports and which versions the builder marks as unsupported now.
- A statement of which accounts the system holds and which of them checked in during the same month.
- A statement of what an attacker would want from the design and which paths the design leaves open to that goal.