Section 25: Vulnerability Management Flashcards
1
Q
Vulnerability Assessment vs Penetration Test
A
● Vulnerability Assessment
o Credentialed
● Penetration Test
o Non-credentialed
2
Q
Double-Blind Penetration Test
A
Double-Blind Test
▪ Much like the blind test, except the defenders are not informed about when the attack may occur
3
Q
Scope of Work (SOW)
A
▪ Details the tasks to be performed which will include all the rules of
engagement that will be followed
4
Q
Rules of Engagement (ROE)
A
▪ The ground rules both parties must abide by
● Timeline
● Location
● Time restrictions
● Transparency
● Boundaries
● Test Invasiveness
5
Q
Software Composition Analysis
A
▪ The assessor inspects the source code to try to identify any open source component