Chapter 5 Security Assessment & Testing Flashcards
Which one of the following security assessment techniques assumes that an organization has already been compromised and searches for evidence of that compromise?
A. Vulnerability scanning
B. Penetration testing
C. Threat hunting
D. War driving
C. Threat Hunting
Renee is configuring her vulnerability management solution to perform credentialed scans of servers on her network. What type of account should she provide to the scanner?
A. Domain administrator
B. Local administrator
C. Root
D. Read-only
D. Read-only
Ryan is planning to conduct a vulnerability scan of a business-critical system using dangerous plug-ins. What would be the best approach for the initial scan?
A. Run the scan against production systems to achieve the most realistic results possible.
B. Run the scan during business hours
C. Run the scan in a test environment
D. Do not run the scan to avoid disrupting the business.
C. Run the scan in a test environment
Which one of the following values for the CVSS attack complexity metric would indicate that the specified attack is simplest to exploit?
A. High
B. Medium
C. Low
D. Severe
C. Low
Tara recently analyzed the results of a vulnerability scan report and found that a vulnerability reported by the scanner did not exist because the system was actually patched as specified. What type of error occurred?
A. False positive
B. False negative
C. True positive
D. True positive
A. False positive
Brian ran a penetration test against a school’s grading system and discovered a flaw that would allow students to alter their grades by exploiting a SQL injection vulnerability. What type of control should he recommend to the school’s cybersecurity team to prevent students from engaging in this typeof activity?
A. Confidentiality
B. Integrity
C. Alteration
D. Availability
B. Integrity
Which one of the following security assessment tools is least likely to be used during the reconnaissance phase of a penetration test?
A. Nmap
B. Nessus
C. Metasploit
D. Nslookup
C. Metasploit
During a vulnerability scan, Brian discovered that a system on his network contained this vulnerability:
Solution: customers are advised to refer to Microsoft Advisory MS17-010 for more details patch
What security control, if deployed, would likely have addressed this issue?
A. Patch management
B. File integrity monitoring
C. Intrusion detection
D. Threat hunting
A. Patch management
Which one of the following tools is most likely to detect an XSS vulnerability?
A. Static application test
B. Web application vulnerability scanner
C. Intrusion detection system
D. Network vulnerability scanner
B. Web application vulnerability scanner
During a penetration test, Patrick deploys a toolkit on a compromised system and uses it to gain access to another systems on the same network. What term best describes this activity?
A. Lateral movement
B. Privilege escalation
C. Footprinting
D. OSINT
A. Lateral movement
Kevin is participating in a security exercise for his organization. His role in the exercise is to use hacking techniques to attempt to gain access to the organization’s systems. What role is Kevin playing in this exercise?
A. Red Team
B. Blue Team
C. Purple Team
D. White Team
A. Red Team
Which one of the following assignment techniques is designed to solicit participation from external security experts and reward them for discovering vulnerabilities?
A. Threat hunting
B. Penetration testing
C. Bug Bounty
D. Vulnerability scanning
C. Bug bounty
Kyle is conducting a penetration test. After gaining access to an organization’s database server, he installs a backdoor on the server to grant himself access in future. What term best describes this action?
A. Privilege escalation
B. Lateral movement
C. Maneuver
D. Persistance
D. Persistance
Which one of the following techniques would be considered passive reconnaissance ?
A. Port scans
B. Vulnerability scans
C. WHOIS lookups
D. Footprinting
C. WHOIS lookups
Which element of the SCAP framework can be used to consistently describe vulnerabilities?
A. CPE
B. CVE
C. CVSS
D. CCE
B. CVE