Pentesting Professional Terms Flashcards

To Explain some coporate or professional speak

1
Q

What is blackbox penetration testing?

A

testing with no knowledge of the infrastructure, configuration or applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is greybox penetration testing?

A

testing with a bit of knowledge roughly equivelant to an employee

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is whitebox penetration testing?

A

testing done with full access to an application or network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is application penetration testing?

A

testing specifically done on an applications such as webapps or apis. Normally the tester is good at source code review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is network penetration testing?

A

Network or infrastructure pentesters assess all aspects of a computer network, including its networking devices such as routers and firewalls, workstations, servers, and applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is physical penetration testing?

A

Physical pentesters try to leverage physical security weaknesses and breakdowns in processes to gain access to a facility such as a data center or office building.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is social engineering penetration testing?

A

Social engineering pentesters test human beings. Can employees be fooled by phishing, vishing (phishing over the phone), or other scams? Can a social engineering pentester walk up to a receptionist and say, “yes, I work here”?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an incident response plan?

A

A pre-planned serious of measures to be taken in the event of a cyber incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a CSIRT?

A

computer security incident response team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a CISO?

A

chief information security officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a CTO?

A

chief technical officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a vulnerability

A

A Vulnerability is a weakness or bug in an organization’s environment, that opens up the possibility of threats from external actors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a CVSS

A

The Common Vulnerability Scoring System is a way of representing the severity of a vulnerability numerically.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is an exploit?

A

An Exploit is any code or resources that can be used to take advantage of an asset’s weakness.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is risk?

A

Risk is the possibility of assets or data being harmed or destroyed by threat actors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly