Keywords Flashcards
What is a pen test
Penetration, testing, attempt to exploit vulnerabilities in order to help, strengthen the security systems of an organization by displaying their weaknesses.
This provides a clear picture of their nature as well.
What are the three different types of information security?
Confidential
Approved individuals may access information
Availability
Insurance information is accessible to all authorized members
Integrity
insures information is correct and unaltered
What is an advanced persistent threat? APT
Detects use innovative tools, and once a system is infected, they silently extract data over an extended period of time(persistent). APTs are most commonly associated with state actors.
Threat actor
An individual or entity responsible for cyber incidence against the technology equipment of enterprises and users
Script kiddies
Individuals who want to perform attack yet like technical knowledge to carry them out
They can be found download in through the available, automated software, and use it to attack
Hacktivists
Individuals that are strongly motivated by ideology, for the sake of their principles or beliefs
State actors
Governments are increasingly employing their own state, sponsored attackers for launching cyber attacks against foes
Many security researchers, think that they are the deadliest of any threat actors
State actors are often involved in multiyear intrusion campaigns targeting highly sensitive, economic, proprietary, or national security information.
Insiders
Employees, contractors, and business partners compose an insider threat of manipulating data from the position of a trusted employee.
These attacks are harder to recognize because they come from within the enterprise.
What is a creep
And expansion beyond the initial set of the test limitations
What is phase 1 of a penetration test called?
Reconnaissance
What are the two parts of phase 1 of a penetration test?
Active and passive reconnaissance
What is active reconnaissance?
Involves directly probing for vulnerabilities and useful information
What is passive reconnaissance?
Passive reconnaissance occurs when the tester uses tools that do not raise any alarms.
This may include searching online for publicly accessible information called open source intelligence (OSINT) that can reveal valuable insight about the system
What is phase 2 of a penetration test called?
And what is it?
Penetration
A pen test is intended to stimulate the actions of threat actor
Footprinting
To perform preliminary information gathering from outside the organization