Ethical Hacking vs. Penetration Testing vs. Auditing Flashcards
1
Q
What is the difference?
A
MOTIVATION “RULES OF ENGAGEMENT”
2
Q
Penetration Testing aka Pentesting aka Red Team
A
Clearly define rules of what is and isn’t allowed
3
Q
Ethical Hacking
A
No rules, ethical disclosure
4
Q
Rules of ethical disclosure
A
- Build Trust - Ethical hacking for the “right reasons”?
- Inform the affected party first - Every effort is made to contact the vendor, giving ample time to fix before public disclosure
- Coordinate efforts - including necessary affected stakeholders
- Maintaining confidentiality where appropriate - observing internal policies, local regulations, and industry best practices
5
Q
Auditing
A
Detail network structure, detect vulnerabilities, assess risk management, prioritize risk
Compliance check, improvements, credibility, prevention fraud, budget