MOD 18 Flashcards

1
Q

What is the process of identifying and prioritizing vunlerabilites in a system?

A

Vulnerability assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which type of testing focuses on penetrating network defenses and getting access?

A

Penetration Testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which Pen Testing area breaches network defenses?

A

Network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which Pen Testing area breaches WiFi networks?

A

WiFi

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which Pen Testing area looks for vulnerabilities in web apps?

A

Web Applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which Pen Testing area looks for ways to get into mobile devices?

A

Mobile

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which Pen Testing area checks for database vulnerabilities?

A

Database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the process of ensuring a system meets the security requirements of its domain?

A

System Accredation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 5 Pen Testing Steps?

A

1) Business and Legal
2) Vulnerability Test
3) Vulnerability Analysis
4) Reporting
5) Remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which rule of behavior focuses on targets, time frames, and rules?

A

Scope of the test

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which rule of behavior limits the approach and attacks?

A

Limitation of Testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which rule of behavior says that specific goals must be set?

A

Criteria for Success

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which knowledge test has an outsider’s view?

A

Zero knowledge test

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which knowledge test is in-between zero and full knowledge test?

A

partial knowledge test

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which knowledge test has what employees might see?

A

Full knowledge test

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which rule of behavior handles incidents created by the pen testing team?

A

Incident Response

17
Q

Which rule of behavior specifies which summaries and recommendations will be provided?

A

Reporting

18
Q

What is the passive method of learning about an organization?

A

Footprinting

19
Q

What is passively identifying computers, ports, and services?

A

Scanning

20
Q

Leaving a way for later priviledged access is called a _________.

A

Back Door

21
Q

Which organization identifies vulnerabilities to services and ports?

A

National Vulnerability Database (NVD)

22
Q

Which organization classifies and scores new vulnerabilities?

A

Common Weakness Enumeration (CWE)

23
Q

Which certification is extremely hard and requires an actual penetration test?

A

OSCP

24
Q

Which certification is from EC-Councel and is a multiple choice exam?

A

CEH

25
Q

Which certification has exams offered by SANS when you take their classes?

A

GPEN

26
Q
A