Penetration Testing Flashcards

1
Q

Penetration testing

A

Exploits weakness

Reconnaissance first step
Active reconnaissance -interacts with the system and network can be seen by attackers

Passive Reconnaissance- using tools not detected by network or hacker

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Reconnaissance

A

Topology discovery-discovering devices in the network

Service discovery- determining what services are running on a system

IS fingerprinting determine the operation system

Reviewing log- info whether packets are accepted dropped or denied

Packet capture- establishing a network baseline

Social engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Pivoting

A

The ability of an attacker to move thru the network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Pivoting exploitation

A

Exploiting a vulnerability

Commonly performed by pivoting and escalation of privilege

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Escalation of privilege

A

Vertical
Elevated permissions
Lower to higher(user to admin)

Horizontal
From oan account in one group to a similar account in another group with out the same privileges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Persistence

A

Creating a back door to evade normal authentications

Apt- advanced persistence threat

Invisibility and persistence

Actors are patient

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Penetration testing box types

A

Black box test- test software functionality- no knowledge(zero day)

White box test- testers have detailed knowledge- simulates insider attacks

Gray box test- thought of as a hybrid of black and white testing

Testers have some limited knowledge of software network and systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Blind vs double

A

Blind-
Attackers have no knowledge of the network defenders do

Double blind test
Neither side knows anything

How well did you know this?
1
Not at all
2
3
4
5
Perfectly