Threats & Vulnerabilities Flashcards

(7 cards)

1
Q

What is a zero-day attack?

A

An exploit unknown to the vendor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the MITRE ATT&CK framework?

A

A database of adversary tactics, techniques, and procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is vulnerability scanning and how is it done?

A

Automated scan to detect system weaknesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A user receives an email that appears to be from IT asking for their login credentials. What kind of attack is this?

A

Phishing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A vulnerability was exploited before a patch was available. What is this called?

A

Zero-Day Attack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the purpose of MITRE ATT&CK?

A

To catalog and analyze attacker tactics and techniques

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an advantage of performing a vulnerability scan?

A

Identify known weaknesses without exploiting them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly