LP - Vulnerability Management Flashcards

1
Q

SAMM stands for

A

software assurance maturity model

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

DAST use web scanners like

A

OWASP ZAP and Buro Suite (vulnerability scanners)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SentinelOne is what

A

website with information on security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Software used in cypersecurity

A

Maltego - graphic of website links
NIST - vulnerability databse has CDE
SANS - also has policy templates
Mitre - has an attack matrix

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Package Monitoring?

A

processes and tools that troubleshoot application performance issues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Pent Testing - pre-engagement meeting elements

A
  • scope and restrictions
  • pricing
  • black or white box testing
  • credentialed vs non-credentialed
  • bug bounty
  • Intrusive or non-intrusive
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Penetration testing lifecycle

A
  1. Information gathering or reconnaissance
  2. Threat modeling
  3. Vulnerability analysis
  4. exploitation
  5. Post exploitation
  6. Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly