Your question is Threat Model Sensitive File Microservice. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
Walk me through how you would threat model a newly designed microservice at Canva that handles sensitive user-uploaded file processing.
Cover the assets, trust boundaries, attacker capabilities, STRIDE threats, prioritized mitigations, and verification methods. Explain how your design handles malicious files, compromised workloads, downstream integrations, sensitive output, and incident response.