Performing Vulnerability Analysis Flashcards

1
Q

Security Content Automation Protocol(SCAP)

A

A NIST framework that outlines various accepted practices for automating vulnerability scanning.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Open Vulnerability and Assessment Language(OVAL)

A

An XML schema, maintained by MITRE, for describing system security state and querying vulnerability reports and information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Common Platform Enumeration(CPE)

A

Scheme for identifying hardware devices, operating systems, and applications developed by MITRE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Common Vulnerabilities and Exposures(CVE)

A

Scheme for identifying vulnerabilities developed by MITRE and adopted by NIST.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Common Configuration Enumeration(CCE)

A

Scheme for provisioning secure configuration checks across multiple sources developed by MITRE and adopted by NIST.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Common Vulnerability Scoring System (CVSS)

A

A risk management approach to quantifying vulnerability data and then taking into account the degree of risk to different types of systems or information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly