Lecture2 Industry Threats & Measuring Risk Flashcards
1
Q
Web Application and Cloud Security vulnerabilities
predominately come from……
A
poor coding practices
Also: unpatched systems & misconfigurations
2
Q
How many more times expensive to fix a vulnerability during post-production than during design ?
A
30x
3
Q
Bug bounties cost from …. to …
A
$50 - thousands
4
Q
Most prevalent Cloud and Web Application Security Threat?
Which causes the most harm?
A
XSS - most prevalent
SQLi - most harm
5
Q
Industry standards?
A
OWASP, MITRE, SANS
6
Q
4 projects are …
A
OWASP top ten, OWASP testing guide, Security shepherd, Zed Attack Proxy or Burp Suite (not OWASP)