Penetration testing Flashcards

1
Q

What is penetration testing?

A

This is testing a organizations resistance to external attacks, by exploiting vulnerabilities in the security systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is white box testing?

A

This is operated as and insider threat, knowing such as platform systems configuration, opearting system, hardware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is black box testing?

A

This is done by a external threat view less knowledge of the environment and requires recon and discovery, ideally testers should have similar skill levels as the attackers you might have

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what is gray box testing?

A

This is middle of the road approach that borrows from both black/white box , this could be done for time constraints, or testing a certain system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the rules of engagment?

A

Defines the parameters of the test, scoping of the when and what, also gives a timeline for the test, and lastly when the test will proceed and set the legal concerns. As well as third party concerns

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Phases of penetration testing

A

Recon>Initial access>privilege escalation>Pivoting/lateral movement>Maintain persistence>Reporting>Cleanup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Penetration testing - cleanup

A

Closing out penetration test, putting everything back the way it was

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what are bug bounties?

A

Its responsible disclosure programs, this is outside testing, and help discover vulnerabilities, and provide incentive to testers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly