Chap 1 Flashcards

1
Q

4 major phases of CompTIA’s pentest testing process

A

Planning and scoping; information gathering; and vulnerability identification; attacks and exploits; and reporting and communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Other name for pen test

A

Ethical hacking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A protection element, such as permissions or firewall, designed to keep unauthorized individuals out of a system of network

A

Security control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What step is the most important in a successful pentest report?

A

Remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PCI DSS best practices requirements for pen testing

A

-perform annual (external and internal) pen test, complete remediation actions
-bi annual pen test conducted for network segmentation controls

-(also internal testing whenever changes are made in network infrastructure or applications)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

2 main trains to perform pen test

A

-get an accurate picture of the results of an attack
-to be in compliance with industry regulations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Performs attacks on assets

A

Red team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Protecting assets

A

Blue team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Separation of duties and no direct conflict of interests is important in conducting a pen test. Which is why a separate security team should be the ones to test the security controls rather than the team who ________

A

Installed, configured, and manages the systems or networks. And should not be the ones implanting the security of the system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Pros and cons of either internal or external 3rd party conducting pen test

A

Pros of internal team:
Cheaper and allows for more regular tests

Pros of external 3rd party:
Not familiar with infrastructure, similar to a hacker
Fresh eyes evaluating your defense

Cons of 3rd party:
What are their qualifications? Will results be confidential? Cost?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly