chapter 5 - Security Assesment and Testing Flashcards

1
Q

SCAP

A

Security
Content
Automation
Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CVE

A

Common Vulnerabilities & Exposures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CVSS

A

Common
Vulnerability
Scoring
System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ASV

A

approved
scanning
vendor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

NIST

A

national
institute
of
standards
and
technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ASV

A

approved
scanning
vendor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SCAP (elements)

A

CPE
CCE
CVE
XCCDF
CVSS
OVAL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CPE

A

common
platform
enumeration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

CCE

A

common
configuration
enumeration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

XCCDF

A

extensible
configuration
checklist
description
format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

OVAL

A

OPEN
VULNERABILITIES
AND
ASSESMENT
LANGUAGE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

vulnerability scanners

A

web
app
ntw

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

WEB APP SCANNING

A
  • SQL INJECTION
  • CROSS-SITE SCRIPTING (XSS)
  • CROSS-SITE REQUEST FORGERY (CSRF)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

APP SCANNING

A

STATIC
DYNAMIC
INTERACTIVE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ntw vul. scanner

A

1 NESSUS
2 QUALYS (SaaS mgmt console - on premises+in the cloud)
3 RAPID7’ NEXPOSE
4 OPENVAS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

XSS

A

cross-site scripting

17
Q

CSRF

A

cross-site request forgery

18
Q

web app scanners

A

NIKTO - open source
ARACHNI - open source
ACUNETIX - commercial
=========================
most orgs use web app scanning capabilities of traditional ntw vuln scanners:
NESSUS
QUALYS
NEXPOSE

19
Q

ntw vuln scanners

A

NESSUS
QUALYS
RAPID7’s NEXPOSE
OPENVAS

20
Q

CVSS SEVERITY RATING SCALE

A

0.0 NONE
0.1 - 3.9 LOW
4 - 6.9 MEDIUM
7 - 8.9 HIGH
9 - 10 CRITICAL

21
Q

SOC

A

security
operations
center