Section 1: Planning an Engagement Flashcards

1
Q

Vulnerability vs Risk vs Threat

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Risk Handling Strategies

A

Risk Avoidance
Risk Transfer
Risk Mitigation
Risk Acceptance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Risk Appetite vs Risk Tolerance

A

Risk Appetite - Overall generic level of risk the organization is willing to accept
Risk Tolerance - Specific maximum risk the organization is willing to takeabout a specific identified risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Access Control Types

A

Compensative - used in place of primary control
Corrective - reduces the effect (fire extinguishers)
Detective
Deterrent - discourages violation of security policies (security camera)
Directive - Acceptable Use Policy
Preventitive
Recovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Statement of Work

A

A formal document that details the tasks to be performed during an engagement
▪ The statement of work will usually contain the list of deliverables
● Final report
● Responsibilities of the penetration tester and the client
● Schedule
● Timelines for payments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Master Service Agreement (MSA)

A

A specialized type of contract that is used to govern future transactions and agreements

Used if you do a lot of work for the same client repeatedly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Sarbanes-Oxley (SOX)

A

Affects publicly traded U.S. corporations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Gramm-Leach-Bliley Act of 1999 (GLBA)

A

Affects banks, mortgage companies, loan offices, insurance companies, investment companies, and credit card providers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Federal Information Security Management Act of 2002 (FISMA)

A

Affects federal agencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Family Educational Rights and Privacy Act (FERPA)

A

Protects the privacy of student education records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly