5.5 Flashcards

Audits and assessments, penetration tests

1
Q

The provision of an opinion of truth or accuracy of an audit, commonly for cybersecurity

A

Attestation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The group that is responsible for all of the risk management in an organization, and the group that starts and stops internal audits.

A

Audit committee

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The part of an audit that includes viewing records, compiling reports, and gathering specific details about the audit and its scope

Hands-on research

A

Examination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The part of the audit that gets into the trenches of evaluating an organization’s policies and procedures, and how well they are carried out by employees.

This is the part that looks for potential improvements.

A

Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A penetration test that involves attempting to gain access to a building or physical hardware by circumventing physical security procedures

A

Physical penetration test

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The aspect of pentesting that involves attacking systems and looking for vulnerabilities to exploit

AKA the red team

A

Offense

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The aspect of pentesting that involves identifying attacks in real-time and preventing unauthorized access.

AKA the blue team

A

Defense

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The method of pentesting that is the best to use. It involves utilizing both red team and blue team methods to create a constant feedback loop on itself.

A

Integrated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A type of penetration test where the tester is given some information about the systems, applications, and network layout of the organization beforehand.

This is used when you want the tester to be sure to attack certain systems in the organization.

A

Partially known environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A type of penetration test where the tester is given full disclosure of all systems, applications, and network layout of the organization beforehand.

A

Known environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

A type of penetration test where the tester is given no information about the systems, applications, or network layout of the organization beforehand.

The tester goes in blind and figures it out throughout the test.

AKA a “blind” test

A

Unknown environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The process used by a penetration tester to gather as much information as possible about an environment.

Specifically, they look for OS types, what applications are installed, if there are firewalls, how many ports are open, where the routers are, if there are subnets, etc.

A

Reconnaissance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The type of reconnaissance that involves looking for information from open sources. This might involve:

Social media
Corporate websites
Online forums
Social engineering
Dumpster diving
Talking to third-party companies that do business with that organization to discern what they know about the infrastructure

A

Passive reconnaissance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The type of reconnaissance that involves actually going into the network and querying its devices. This involves the risk of being noticed by an IPS or an admin. This might involve:

Ping scans
Port scans
DNS queries
OS scans/OS fingerprinting
Service scans
Version scans

A

Active reconnaissance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly