DREAD
Microsoft's threat-scoring model: Damage, Reproducibility, Exploitability, Affected users, Discoverability, rated on an agreed scale to rank threats a framework such as STRIDE has already found.
Full guide: STRIDE Threat Model Explained: The Six Categories and What They Break for CISSP
DREAD is a threat-scoring model used to rank threats by severity once they have already been identified. Each threat is rated across five dimensions: Damage, how bad a successful attack would be; Reproducibility, how easily it can be repeated; Exploitability, how much effort or skill it takes; Affected users, how many people it would hit; and Discoverability, how easily the weakness can be found.
The five scores are rated on a scale the team agrees in advance, commonly 1 to 10, then summed or averaged into one rating. A higher rating supports a higher treatment priority rather than dictating it, since business context, cost and obligations all bear on what is actually fixed first. Because the scale is a local convention, scores from different teams are not comparable with each other.
The pairing that matters is with STRIDE, which categorises threats but does not rank them. STRIDE produces the list and DREAD is one way of ordering it, which is why the two are taught together as steps in one threat modeling exercise rather than as competing frameworks. DREAD is not the only option, and Microsoft itself later moved away from numeric scoring of this kind because assessors struggled to apply it consistently.
Exam relevance: a scenario that hands you a completed list of threats and asks what to do next is generally pointing at a scoring model rather than at repeating the enumeration. DREAD’s structure is its strength, since common criteria make assessments more systematic and comparable than unaided judgement, and its scores are its weakness, since two assessors can rate the same threat differently. Read the numbers as a way of comparing threats, not as objective measurements of risk.