Prelim - Pen Testing Flashcards

1
Q

Penetration Testing

A

An attempt to exploit vulnerabilities to determine whether unauthorized access or other malicious activity is possible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Computer System Servers/Networks, Applications Vulnerabilities

A
  1. Design and implementation
  2. Poor system configuration
  3. Insecure network
  4. System complexity
  5. Human errors - coding errors
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Primary purpose of Penetration Testing

A
  1. To discover vulnerabilities
  2. Test for security compliance
  3. Verify staff awareness
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Penetration Testing Types

A

Web Application
Network Services
Social Engineering
Client Side

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Types of Penetration Testing Based on Knowledge of Target

A
  • Black Box testing
  • Grey Box Testing
  • White Box Testing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Black Box testing

A

Zero Knowledge of Target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Grey Box Testing

A

Some Knowledge of Target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

White Box Testing

A

Full Knowledge of Target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Types of Penetration Testing Based on Position of Penetration Tester

A

External Penetration Testing
Internal Penetration Testing
Targeted
Blind Test
D-Blind

How well did you know this?
1
Not at all
2
3
4
5
Perfectly