Security: Information Gathering Flashcards

1
Q

DIG TYPES

A

A = IPV4 address record

AAAA = IPv6

CNAME = canonical name record

MX = mail exchange

PTR = pointer resource record

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

DIG ERRORS

A

NO ERROR

SERVFAIL

NXDOMAIN

REFUSED

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

NXDOMAIN Error

A

name queried does not exist and no authoritative DNS data to be served

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

REFUSED Error

A

zone does not exist at the request authority and their infrastructure is not serving things that don’t exist at all

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Cyber Kill Chain steps

A
  1. Reconnaissance
  2. Intrusion
  3. Exploitation
  4. Privilege escalation
  5. Lateral movement
  6. Obfuscation/Anti-Forensics
  7. Denial of Service
  8. Exfiltration
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Three types of exploitation

A
  1. Code
  2. Misconfiguration
  3. Human
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Code exploitation

A

taking advantage of a flaw within a program’s instructions and manipulating it in a manner that was not intended by the creators

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Misconfiguration

A

a system’s setting that allows it to be manipulated by an unintended source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly