Bonus Learning Flashcards
1
Q
What are the benefits of threat hunting? (5)
A
Improve detection capabilities
Reduce attack surface
Block attack vectors
Identify important assets
Better security posture
2
Q
List the steps in the risk analysis process.
A
- Identify assets and their value
- Identify vulnerabilities and threats
- Quantify the probability and impact of the identified threats
- Balance the impact of the threat against the cost of the control or countermeasure.
3
Q
What are the four steps in the risk management process?
A
- Identify threats
- Assess the risk
- Respond to the risk
- Monitor the risk.
4
Q
Threat Modeling Steps
A
- Identify Assets
- Outline Architecture
- Decompose the Application
- Identify Threats
- Determine and Ranks Threats
- Determine Countermeasures and Mitigation
5
Q
Name the Steps of DREAD
A
Damage, Reproducibility, Exploitability, Affected Users, Discoverability
6
Q
What is the Process for Attack Simulation and Threat Analysis known as?
A
PASTA
7
Q
A