Enpoint Vulnerability Quiz Flashcards
In profiling a server, what defines what an application is allowed to do or run on a server?
Service accounts
In network security assessments, which type of test is used to evaluate the risk posed by vulnerabilities to a specific organization including assessment of the likelihood of attacks and the impact of successful exploits on the organization?
Vulnerability assessment
When a network baseline is being established for an organization, which network profile element indicates the time between the establishment of a data flow and its termination?
Session duration
Which type of evaluation includes the assessment of the likelihood of an attack, the type of threat actor likely to perpetrate such an attack, and what the consequences could be to the organization if the exploit is successful?
Risk Analysis
A cybersecurity analyst is performing a CVSS assessment on an attack where a web link was sent to several employees. Once clicked, an internal attack was launched. Which CVSS Base Metric Group Exploitability metric is used to document that the user had to click on the link in order for the attack to occur?
User Interaction
Which metric class in the CVSS Basic Metric Group identifies the impacts on confidentiality, integrity, and availability?
impact
Which metric in the CVSS Base Metric Group is used with an attack vector?
the proximity of the threat actor to the vulnerability
Which statement describes the threat-vulnerability (T-V) pairing?
It is the identification of threats and vulnerabilities and the matching of threats with vulnerabilities.
In addressing an identified risk, which strategy aims to shift some of the risk to other parties?
Risk Sharing
Which step in the Vulnerability Management Life Cycle categorizes assets into groups or business units, and assigns a business value to asset groups based on their criticality to business operations?
prioritise assets
What is an action that should be taken in the discovery step of the vulnerability management life cycle?
developing a network baseline