Section 25: Vulnerability Management Flashcards

1
Q

Vulnerability Assessment vs Penetration Test

A

● Vulnerability Assessment
o Credentialed

● Penetration Test
o Non-credentialed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Double-Blind Penetration Test

A

Double-Blind Test
▪ Much like the blind test, except the defenders are not informed about when the attack may occur

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Scope of Work (SOW)

A

▪ Details the tasks to be performed which will include all the rules of
engagement that will be followed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Rules of Engagement (ROE)

A

▪ The ground rules both parties must abide by
● Timeline
● Location
● Time restrictions
● Transparency
● Boundaries
● Test Invasiveness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Software Composition Analysis

A

▪ The assessor inspects the source code to try to identify any open source component

How well did you know this?
1
Not at all
2
3
4
5
Perfectly