Lecture 4 Flashcards
What is the main purpose of prerequisites in Vulnerability Assessment (VA)?
To ensure the smooth conduct of the Vulnerability assessment
Prerequisites help in organizing the assessment effectively.
What is the importance of target scoping in Vulnerability Assessment?
Defines what will be assessed
A proper scope prevents scope creep, customer dissatisfaction, and legal trouble.
What is an Asset Table in the context of Vulnerability Assessment?
A list of critical assets that need to be assessed
It should include all relevant assets, although not every asset may be practically included.
What 3 factors determine asset criticality?
- Asset’s monetary value
- Legal standing
- Importance to the organization
Critical assets include hardware, servers, sensitive information, and business trade secrets.
- Communication lines
- E-commerce platforms
- Internet-facing websites
Within the context of an enterprise, these assets are considered ________
Critical
These assets must be included in the vulnerability assessment.
- Applications and application APIs
- Mail servers
- Database servers
- Web servers
Within the context of an enterprise, these assets are considered ________
Critical
What are non-critical assets in Vulnerability Assessment?
Assets that are usually ignored but could be exploited by attackers
Examples include security cameras, smart devices, printers, and wireless access points.
- Security compliance desired by the customer
- Requirements and code of conduct
- List of subnets in the scope
How do these points relate to meeting customers?
These are ideal learning outcomes when meeting a customer.
This ensures clarity on the customer’s needs.
- Network security devices in scoped network segments
- Assets to scan and their IP range
How do these points relate to meeting customers?
These are ideal learning outcomes when meeting a customer.
What is the data lifecycle?
Creation -> Classification -> Access Control Management -> Destruction
Understanding the lifecycle is essential for effective data governance.
Fill in the blank: A detailed outline of the scope will help the _______ plan resources and a time schedule.
vulnerability assessment team