22questions - Sheet1 Flashcards
Which of the following password compliance tools is a password Recovery tool, sniffs network for hashes, and dumps protected storage passwords?
Cain & Able
True or False, the input file for the password compliance script is a SAM file
TRUE
True/False: CAT III are Vulnerabilities that provide information which have a high potential of giving
access to an intruder.
FALSE
Which of the following password compliance tools dumps LM/NTLM hashes from Security Accounts
Manager (SAM) File in Windows, persists in memory, and if used against a domain controller, the
domain controller may need restarting?
PWDump6
True or False. Compliance scans are executed after an initial scan
TRUE
The name of the STIG complainance scan policy for windows 7 is called _________.
win_7_stig
Which is one of the considerations regarding using Nessus to conduct a CE on Windows?
False positives
Which of the following is the nessus configuration file?
.nessus.conf
Which command is used to determine a failed nessus scan
LO-03 Provided a failed Nessus scan result…
nbe-status.sh
Which common plugin number is for Inadequate credentials
24786
To ensure findings are reported correctly and not as false positives is part of what?
Manual Validation
What is the type of table used to submit results
Pivot
True/False: The 92d summarizes all CVA findings within a turn table.
FALSE
How is data organized during the assessment?
A pivot table via a spreadsheet
Which “.ips” file is used for a patch compliance scan
win.ips
True or False, the MAC address needs to be configured for the Nessus Server LO-01 Setup the Nessus server and verify it is operational
TRUE
One of the first steps in executing an initial scan is to create a ________ directory.
LO-02 Provided with valid credentials and a target system execute an initial_scan
working
Why is manual validation important concerning compliance findings?
It promotes due diligence to eliminate false positives and false negatives
What is the name of the script for password compliance?
sam-stat.sh
True/False: The name of the policy for the patch compliance scan is win_all.
TRUE
What command can be used to check the nessus server is operational?
netstat
Which is one of the limitations regarding using Nessus to conduct a CE on Windows?
Nessus can only detect what you program it to see and may introduce false negatives