Security Assessment Flashcards

1
Q

What is a security Assessment?

A

An examination of your security posture, practices and anything else related against industry standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does it entail in a vulnerability assessment?

A

Review of:
exisiting configuration
code
software
architecture
design
dependencies

You need to see how all these things work together.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a vulnerability scanners?

A

Network scanning application that list inventory of systems of network and the details of that system.

It scans any ports open and compare it with vulnerabilities in a database.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a CVSS?

A

Common Vulnerability scoring system - a system for scoring vulnerability on their severity.

This is used to help us which CVEs need to be patched first.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a SIEM?

A

Security information and event management. Centralize solutions for all your logs.

Log collections
Analyze logs for anomalies
Generate alarms and notifications based on patterns

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you verify the integrity of logs?

A

Checking the hash.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a SOAR?

A

Security orchestration, automation and response.

Integrates security tools, processes and technologies to improve the efficiency and effectiveness of incident response and threat management.

This helps us to automate responses without human interventions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly