Network Security Testing Flashcards

1
Q

Vulnerability Scanners

A

A vulnerability scanner assesses computers, computer systems, networks or applications for weaknesses.

Vulnerability scanners can help to automate security auditing by scanning the network for security risks and producing a prioritized list to address vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What types of vulnerabilities do scanners look for?

A
  • Use of default passwords (common passwords)
  • Missing patches
  • Open ports
  • Misconfiguration in operating systems and software
  • Active IP addresses, including any unexpected devices connected
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are some commonly used vulnerability scanners on the market?

A
  • Nessus
  • Retina
  • Core Impact
  • GFI LanGuard
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Categories of scanners

A
  • Network scanners
  • Application scanners
  • Web application scanners
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Network scanners

A

Probe hosts for open ports, enumerate information about users and groups and look for vulnerabilities on the network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Application Scanners

A

Access application source code to test an application from the inside.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Web application scanners

A

Identify vulnerabilities in web applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Intrusive scans

A

Try to exploit vulnerabilities and may even crash the target.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Non-intrusive scan

A

Will try not to cause any harm to the target.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

credentialed scan

A

usernames and passwords provide authorised access to a system, allowing the system to harvest more information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Non-credentialed scan

A

less invasive and give an outsider’s point of view.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly