Planning and Scoping Flashcards

1
Q

steps in pentest methodology

A

planning scoping, info gathering and vuln id, attacks and exploits, reporting and comms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NIST 800-15

A

plan, discover, attack, report with a loop on attack and discover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Project triangle

A

cost, time, money

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

planning doc considerations

A

who is target (objectives), budget, resources, Communication path, end state (deliverable), Technical constraints, Disclaimers (Point-in-time, comprehensiveness)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

SOW

A

Formal document stating scope of what will be performed during a penetration test

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Master Service Agreement (MSA

A

Contract where parties agree to most of the terms that will govern future actions. If you do service over and over.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Non-Disclosure Agreement (NDA)

A

Legal contract outlining confidential material or information that will be shared during the assessment and what restrictions are placed on it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Rules of Engagement

A
Timeline 
▪ Locations 
▪ Time restrictions 
▪ Transparency 
▪ Test boundaries
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Wassenaar Agreement

A

precludes the transfer of technologies considered
“dual-use”
▪ Strong encryption falls under this restriction
▪ Penetration testing tools could be considered surveillance tools and fall
under these rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly