Eth H Flashcards

1
Q

What is an external network pentest?

A

Looking at an organization’s security from the outside of an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does OSINT stands for?

A

Open Source Intelligence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

On what methodology does the external network pentest focuses heavily?

A

On OSINT Gathering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What examples are there of an external network pentest?

A

Hacking the target server from another country, from another office or a house.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does OSINT Gathering consist in?

A

On gathering as much intel and data about an organization.
Their employees, their email format.

Have they ever been involved in a breach? If so can we have access to the breached data? Were there any passwords among that data?
Is there any data we can collect to breach a login panel or breach a VPN o r breach any area we otherwise would not be allowed into?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an internal network pentest?

A

Assessing the organization´s security from inside of the network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What example could there be for an internal network pentest?

A

A phishing email or a person who actually had access to the building could leave some unwanted software. This already gives access to the network. And what we test is what else can we breach after that.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

On what methodology do internal network pentests primarily focus on?

A

On Active Directory Attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a web application pentest?

A

Its assessing an organization’s web applications’ security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

On what methodology do web application pentests primarily focus on?

A

On web-based attacks and on the OWASP testing guidelines.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does OWASP stands for?

A

Open Web Applications Security Project

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a Wireless pentest?

A

Its assesing an organization’s wireless network security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

On what factors does the methodology used for a wireless pentest depends on?

A

On the wireless type being used
(guest vs WPA-PSK vs WPA2 Enterprise)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What device do you need to perform wireless pentests?

A

A wireless network adpater

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a physical pentest?

A

Assessing an organization’s physical security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

On what factors does the methodology used for physical pentests depends on?

A

On tasks and goals set by the client.

17
Q

Mention other types of assesments that a pentester may perform:

A

Mobile Penetration Testing
IoT Penetration Testing
Red Team Engagements
Purple Tem Engagements

18
Q

What is report writing for?

A

To communicate findings and recommendations from pentest assessment.

19
Q

How much time is it typically expected for a report writing to be delivered in?

A

About a week after the engagement ends.

20
Q

What are the 2 types of findings that the report should highlight?

A

Non-technical (executive) and technical findings.

21
Q

How should the recommendations be in the report writing?

A

Recommendations for remmediation should be as clear as possible for both, the executive viewpoint and the technical staff viewpoint.

22
Q

How is a debrief performed?

A

A debrief is basically the walthrough of your report findings. This is done for both technical and non-technical staff.

Debrief must be able to be explained at a high-level and at a low-level depending on an audience.

23
Q

Why is the debrief important?

A

Because it gives the client an opportunity to ask questions and address any concerns they might have.