chapter 5 - Security Assesment and Testing Flashcards
1
Q
SCAP
A
Security
Content
Automation
Protocol
2
Q
CVE
A
Common Vulnerabilities & Exposures
3
Q
CVSS
A
Common
Vulnerability
Scoring
System
4
Q
ASV
A
approved
scanning
vendor
5
Q
NIST
A
national
institute
of
standards
and
technology
6
Q
ASV
A
approved
scanning
vendor
7
Q
SCAP (elements)
A
CPE
CCE
CVE
XCCDF
CVSS
OVAL
8
Q
CPE
A
common
platform
enumeration
9
Q
CCE
A
common
configuration
enumeration
10
Q
XCCDF
A
extensible
configuration
checklist
description
format
11
Q
OVAL
A
OPEN
VULNERABILITIES
AND
ASSESMENT
LANGUAGE
12
Q
vulnerability scanners
A
web
app
ntw
13
Q
WEB APP SCANNING
A
- SQL INJECTION
- CROSS-SITE SCRIPTING (XSS)
- CROSS-SITE REQUEST FORGERY (CSRF)
14
Q
APP SCANNING
A
STATIC
DYNAMIC
INTERACTIVE
15
Q
ntw vul. scanner
A
1 NESSUS
2 QUALYS (SaaS mgmt console - on premises+in the cloud)
3 RAPID7’ NEXPOSE
4 OPENVAS