Lesson 17 - Communicating During the PenTest Flashcards
What is the most effective way to identify false positives
Using Results Validation - compare what you learned about the target environment to individual scan results
If your PenTest is discovered what is the one way to address this
Through De-escalation and scale it back so you can proceed
What is the name of the standard that can be used for presenting the findings
PTES - Penetration Testing Execution Standard
for example
Vulnerability Class Levels
Technical Vulnerabilities
Logical Vulnerabilieis
Summary
What is the tool/platform that can be used to share data and collaborate on a PenTest called
Dradis
What is the vulnerability scanner tool that has a module dedicated to reporting
Tenable’s Nessus Platform
Name some of the logical vulnerabilities a PenTester may identify
Non-OSI
Type of Vulnerability - is a logical