CYBERSECURITY FOUNDATIONS | CAPSTONE
Capstone: threat-model and harden a small application
Learn how capstone: threat-model and harden a small application works in Cybersecurity Foundations, why the underlying model matters, and how to apply it in a small program without hiding important trade-offs.
What you will learn
- Explain threat-model in Cybersecurity Foundations using the correct mental model
- Trace a focused Cybersecurity Foundations example and predict its result before execution
- Recognize a boundary case involving harden a small application and handle it deliberately
The concept
Capstone: threat-model and harden a small application is a defining part of practical Cybersecurity Foundations work. Start by identifying the data or state involved, then trace the operation that changes or interprets it. Pay attention to the rules Cybersecurity Foundations applies at this boundary, because those rules explain both the useful behavior and the common failure modes. This lesson keeps the example deliberately small, then connects it to capstone: threat-model and harden a small application so the ideas form a coherent progression rather than a list of isolated syntax facts.
Explain threat-model in Cybersecurity Foundations using the correct mental model.
Example
This example is intentionally small so you can trace every line before adapting it.
# Model an input boundary
trusted = False
print('Validate before use')
// Lesson 16: threat-model. Change one value and predict the result before running it.Read it step by step
- 1Locate the idea
Identify where threat-model appears in the Cybersecurity Foundations example and name the data it operates on.
- 2Trace the rule
Trace the relevant Cybersecurity Foundations rule one operation at a time, recording any state, type, or control-flow change.
- 3Test a boundary
Change one input or boundary condition, predict the result, and compare that prediction with the documented outcome.
Common mistakes
Treating threat-model as punctuation to memorize instead of a Cybersecurity Foundations behavior to reason about.
Ignoring harden a small application until it appears in production data or a larger program.
Try it yourself
Apply this lesson deliberately
Create a small Cybersecurity Foundations example that demonstrates threat-model. Add a normal case and a boundary case, write down the expected result for each, then explain which Cybersecurity Foundations rule produces that result. Lesson 16 should remain small enough to trace without guessing.
Open Cybersecurity Foundations workspace