What is a cybersecurity protection plan?
A plan that assesses the vulnerabilities within a network and devices
Who can perform vulnerability assessments?
Internal teams or external groups such as white-hat hackers
What is the purpose of independent third-party reviews?
To verify that all vulnerabilities and threats are mitigated in system designs
What is penetration testing?
Simulating a cyber attack to identify vulnerabilities in a system or network
What do port scanners do?
Scan a computer for open ports that may be exploited by hackers
What is the function of a registry checker?
Performs backups of the registry and checks for errors on start-up
What do website vulnerability scanners search for?
Vulnerabilities such as cross-site scripting (XSS), SQL injection, and insecure server configuration
What is vulnerability detection and management software?
Software that analyzes IT systems for threats and identifies key flaws
What does assessing user vulnerabilities involve?
Auditing access requirements, training completed, and complexity of passwords set by staff
What are the benefits of third-party reviews?
Access to specialist cybersecurity skills and cost savings from preventing attacks
What is the role of a white-hat hacker?
A specialist who performs penetration testing for organizations
What is the OWASP Top 10?
A list identifying the most common threats to web applications
Fill in the blank: Injection flaws involve an interpreter being tricked into executing _______.
unauthorized commands
Fill in the blank: Broken authentication allows for _______ to be exploited.
passwords, keys, and session tokens
Fill in the blank: Sensitive data exposure occurs when data lacks sufficient _______.
protections
Fill in the blank: Security misconfiguration includes insecure default _______.
configurations
True or False: Cross-site scripting involves executing scripts to hijack user sessions.
True
What are the consequences of insufficient logging and monitoring?
Allows continuous attacks, leading to further data tampering and destruction