5. Security Assessment and Testing Flashcards

1
Q

SCAP

A

Security Automation Protocol

An effort by the security community, led by the National Institute of Standards and Technology (NIST) to create a standardized approach for communicating security-related information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CCE

A

Common Configuration Enumeration

Provides a standard nomenclature for discussing system configuration issues.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CPE

A

Common Platform Enumeration

Provides a standard nomenclature for describing product names and versions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CVE

A

Common Vulnerabilities and Exposures

Provides a standard nomenclature for describing security-related software flaws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

CVSS

A

Common Vulnerability Scoring System

Provides a standardized approach for measuring and describing the severity of security-related software flaws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

XCCDF

A

Extensible Configuration Checklist Description Format

A language for specifying checklists and reporting checklist results.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

OVAL

A

Open Vulnerability and Assessment Language.

A language for specifying low-level testing procedures used by checklists.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Static Testing

A

Analyzes code without executing it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Dynamic Testing

A

Executes code as part of the test.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Interactive Testing

A

Combines Static and dynamic testing, analyzing the source code while testers interact with the application through exposed interfaces.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly