Ethical Hacking vs. Penetration Testing vs. Auditing Flashcards

1
Q

What is the difference?

A

MOTIVATION “RULES OF ENGAGEMENT”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Penetration Testing aka Pentesting aka Red Team

A

Clearly define rules of what is and isn’t allowed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Ethical Hacking

A

No rules, ethical disclosure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Rules of ethical disclosure

A
  1. Build Trust - Ethical hacking for the “right reasons”?
  2. Inform the affected party first - Every effort is made to contact the vendor, giving ample time to fix before public disclosure
  3. Coordinate efforts - including necessary affected stakeholders
  4. Maintaining confidentiality where appropriate - observing internal policies, local regulations, and industry best practices
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Auditing

A

Detail network structure, detect vulnerabilities, assess risk management, prioritize risk

Compliance check, improvements, credibility, prevention fraud, budget

How well did you know this?
1
Not at all
2
3
4
5
Perfectly