LP - Vulnerability Management Flashcards
1
Q
SAMM stands for
A
software assurance maturity model
2
Q
DAST use web scanners like
A
OWASP ZAP and Buro Suite (vulnerability scanners)
3
Q
SentinelOne is what
A
website with information on security
4
Q
Software used in cypersecurity
A
Maltego - graphic of website links
NIST - vulnerability databse has CDE
SANS - also has policy templates
Mitre - has an attack matrix
5
Q
What is Package Monitoring?
A
processes and tools that troubleshoot application performance issues
6
Q
Pent Testing - pre-engagement meeting elements
A
- scope and restrictions
- pricing
- black or white box testing
- credentialed vs non-credentialed
- bug bounty
- Intrusive or non-intrusive
7
Q
Penetration testing lifecycle
A
- Information gathering or reconnaissance
- Threat modeling
- Vulnerability analysis
- exploitation
- Post exploitation
- Reporting