Lesson 2 - Defining the Rules of Engagement Flashcards

1
Q

If you want to test your Internal IT Team what is the best assessment type to utilize

A

Red Team vs Blue Team
Adversary vs Defense

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the best strategy if the client wants you to fully act like a Bad Actor

A

Unknown Environment - completely in Dark

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

T or F should the PenTest engagement review any non-security related items such as backups?

A

True - yes. these should all be addressed during the confirmation of the scope.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a requirement for avoiding liabilities during a PenTest Engagement

A

Must ensure Confidentiality based on local, state and Federal requirements such as:
Gramm-Leach-Biley Act (GLBA) requiring financial institutions
Drivers Privacy Protection Act - state DMV
HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the contract that establishes precedence and guidelines for any business documents that are executed between two parties

A

Master Services Agreement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

If a party wants to see details on what is being performed, timeline, deliverables, and expectations of invoicing where would they find that

A

Scope of Work

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the contract that sets the service requirements and PenTest Process

A

Service Level Agreement

processing requirements for confidential and private data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly