Reasons “testing security in” doesn’t work.

Reasons “testing security in” doesn’t work.

List two reasons “testing security in” doesn’t work. 2) Explain how to threat model software you acquire. 3) Explain how to threat model software you build. 4) List two specific non-threat-modeling-driven tests you can perform. 5) What is the key difference between penetration testing and threat modeling?