Pen Testing Flashcards

(7 cards)

1
Q

Name 6 methods of attacking a network

A

Malware
Insecure Cloud
Unpatched software with known vulnerabilities
Web attack
Phishing
Supply Chain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do most attacks on a companies network start?

A

phishing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the ARP protocol?

A

Controls who has what IP address on a network. Works by a host broadcasting an IP address and the host with that address responds with their MAC address.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is ARP spoofing?

A

Hosts on a network will accepts ARP replies even if they did not request them. Therefore a device on a the network can tell all the other devices they are the router, causing the other devices to send their packets to the spoofing device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why is WPA2 insecure?

A

The key is based on the wifi password, a nonce generated by the client and a nonce generated by the access point. The nonces are shared unencrypted and so if an attacker knows the password they can decrypt the traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is PCI-DSS?

A

Payment Card Industry Data Security Standard. A data standard for companies handling credit card information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the requirements laid out in PCI-DSS?

A

Log, monitor and restrict access to cardholder data
Protect data from malware
Test security regularly
Protect stored data and data in transit with cryptography

How well did you know this?
1
Not at all
2
3
4
5
Perfectly