Application Security Flashcards

1
Q

What is the opensource tool Dynatrace uses to detect vulnerabilities?

A

Snyk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the steps to get started with Dynatrace application security?

A
  1. Check to see if there are enough Application Security Units (licenses)
  2. Check permissions for the users
  3. Activate by going to settings => Application Security => Enable runtime vulnerability analytics
  4. Optionally add rules to include or exclude based on conditions.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Dynatrace Security Score (DSS)?

A

DSS is based on CVSS but uses Davis and understanding of the environment to calculate a more accurate score from Modified Attack Vector (MAV), Modified Confidentiality (MC) and Modified Integrity (MI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the possible states of any third-party vulnerability in Dynatrace?

A

In Use: At least 1 process group calls a vulnerable function
Not in Use: Affected process group do NOT call any vulnerable function
Not available: Data is not available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly