Lecture2 Industry Threats & Measuring Risk Flashcards

1
Q

Web Application and Cloud Security vulnerabilities

predominately come from……

A

poor coding practices

Also: unpatched systems & misconfigurations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How many more times expensive to fix a vulnerability during post-production than during design ?

A

30x

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Bug bounties cost from …. to …

A

$50 - thousands

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Most prevalent Cloud and Web Application Security Threat?

Which causes the most harm?

A

XSS - most prevalent

SQLi - most harm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Industry standards?

A

OWASP, MITRE, SANS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

4 projects are …

A

OWASP top ten, OWASP testing guide, Security shepherd, Zed Attack Proxy or Burp Suite (not OWASP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly