(1)Penetration Testing Flashcards

1
Q

What is Penetration Testing?

A

Penetration Testing is where an org does a practice (but not damaging to production systems) attack against an org using the same set of weaponry available to real attackers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When conducting a Penetration Test, what does a Pentester do?

A

A Pentester tries to access particular systems and information and then reports this information to whoever asked them to conduct the test.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who conducts penetration tests?

A

Penetration tests are conducted by either people who work for the company who are doing the test or third party contractors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

If a penetration test is being conducted internally, what needs to be true about the individual conducting it?

An internal pentest is very time consuming.

A

The individual conducting the penetration test on an internal pentest needs to be very skilled.

An internal pentest is very time consuming.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does an external pentest entail?

A

External pentests involve an outside agency but are very expensive to do.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Even though penetration tests are costly and involved, should orgs conduct them and why?

A

Despite the barriers to the pentest, organizations should do them regularly because they are a fantastic indicator of an org’s cybersecurity posture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly