Module 23 Endpoint Vulnerability Assessment Flashcards
What is network profiling?
Session duration, total throughput, typical traffic type, critical asset address space
What is a server profile?
Listening ports, logged in users and accounts, service accounts, software environment
What is Network Anomaly Detection?
Network behavior - large amount of data such as packet flow, features of the packet, etc.
- Big data analytics techniques can be used to analyze data and detect variations
What does network vulnerability testing include?
Risk analysis, vulnerability assessment and penetration testing
What is penetration testing?
Use of hacking techniques and tools to penetrate network defenses
What is vulnerability assessments?
Patch management, host scans, port-scanning and other scans
What is risk analysis
Individuals conduct comprehensive analysis of impacts of attacks on core company assets and functioning
What is CVSS
Common Vulnerability Scoring Sys is a risk assessment tool
What are the CVSS Metric Groups
Base, temporal and environmental metric group
What is the base Metric group
Represents the characteristics of a vulnerability that are constant over time
What is Temporal Metric
Measures the characteristics of a vuln that may change over time, but not environments
What is envir metric group
Measures aspects of a vuln that are rooted in a specific organizations envir
What is considered a high severity rating?
Any vuln that exceeds 3.9
What are some vulnerability information sources?
NVD - National Vulnerability Database , CVE (Common Vulnerabilities and Exposures),
What is risk management?
Selection and Specification of security controls for an organization