Lesson 17 - Communicating During the PenTest Flashcards

1
Q

What is the most effective way to identify false positives

A

Using Results Validation - compare what you learned about the target environment to individual scan results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

If your PenTest is discovered what is the one way to address this

A

Through De-escalation and scale it back so you can proceed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the name of the standard that can be used for presenting the findings

A

PTES - Penetration Testing Execution Standard

for example
Vulnerability Class Levels
Technical Vulnerabilities
Logical Vulnerabilieis
Summary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the tool/platform that can be used to share data and collaborate on a PenTest called

A

Dradis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the vulnerability scanner tool that has a module dedicated to reporting

A

Tenable’s Nessus Platform

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Name some of the logical vulnerabilities a PenTester may identify

A

Non-OSI
Type of Vulnerability - is a logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly