Application Security Flashcards
1
Q
What is the opensource tool Dynatrace uses to detect vulnerabilities?
A
Snyk
2
Q
What are the steps to get started with Dynatrace application security?
A
- Check to see if there are enough Application Security Units (licenses)
- Check permissions for the users
- Activate by going to settings => Application Security => Enable runtime vulnerability analytics
- Optionally add rules to include or exclude based on conditions.
3
Q
What is Dynatrace Security Score (DSS)?
A
DSS is based on CVSS but uses Davis and understanding of the environment to calculate a more accurate score from Modified Attack Vector (MAV), Modified Confidentiality (MC) and Modified Integrity (MI)
4
Q
What are the possible states of any third-party vulnerability in Dynatrace?
A
In Use: At least 1 process group calls a vulnerable function
Not in Use: Affected process group do NOT call any vulnerable function
Not available: Data is not available