Security Assessment and Testing Flashcards
1
Q
Security Assessment
A
Technical Security Testing
Security process assessment
Security Audits
2
Q
Technical Security testing
A
Vulnerability assessment Penetration testing (network, web, physical, wireless) Code Review Phishing exercises Password assessments
3
Q
Server-Side Exploitation Process
A
Performance reconnaissance Network enumeration Port scanning Determine version of OS & services Determine vulnerable service versions Exploit vulnerable services
4
Q
Penetration Testing Process
A
Business process (Scope, rules of engagement) Reconnaissance Scanning - vulnerability assessment Exploitation Post exploitation
5
Q
White box testing
A
software testing method that uses internal algorithms and information to conduct the test
6
Q
Black box testing
A
testing with no inside knowledge of application
e.g. testing against compiled code with no access to source
7
Q
Fuzzing
A
sending unexpected input
ask for username, type in 1000 characters to see if program crashes
8
Q
Security Audits
A
implies that an organization is being measured against a defined standard