Audits and Assesments Flashcards
Define Penetration Testing
Simulated cyber-attack that helps in the assessment of computer systems for exploitable vulnerabilities
Name the different types of penetration testing
> Physical Pentesting
Offensive Pentesting
Defensive Pentesting
Integrated Pentesting
Define Physical Pentesting
It involves testing an organization’s physical security through testing locks, access cards, security cameras, and other protective measures.
Define Offensive Penetration testing (Red Teaming)
it’s a proactive approach that simulates real-world attacks. It seeks and exploits system vulnerabilities so orgs learn to recognize and defend against such threats.
Define Defensive Pentesting (Blue Teaming)
A reactive approach that entails (involves) fortifying systems, identifying and addressing attacks, and enhancing incident response times.
Define Integrated Penetration Testing (Purple Teaming)
Offensive and defensive pentest combined.
Define Reconnaissance
It’s an initial phase where critical information about a target system is gathered to enhance an attack’s effectiveness and success. Such as IP addresses, domain details, mail servers, and any potential security or detection systems.
Define Active Reconnaissance
The attacker engages with the target system directly. It gives more info to the attacker but it also comes with a higher risk of detection.