Security Management Programs and Oversight: Pen Testing Flashcards

1
Q

What is penetration testing?

A

Penetration testing is often a key element during the audit and assessment phase of a management initiative for a security program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Physical

A

Physical: Involves authorized individuals attempting to breach an organization’s physical security measures, such as access controls, barriers, and surveillance systems, to assess vulnerabilities and test the effectiveness of its defenses. This process helps identify potential weaknesses that could be exploited by unauthorized individuals seeking unauthorized access to facilities or sensitive areas.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Offensive

A

Offensive: Offensive penetration testing, often referred to as pen testing or ethical hacking, aims to simulate cyberattacks from the perspective of malicious actors. The goal is to identify vulnerabilities and weaknesses that real attackers could exploit.

Simulate cyber attacks

Red Team

Broad Scope

Reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Defensive

A

Defensive: Defensive penetration testing, also known as blue teaming or defensive security testing, focuses on evaluating an organization’s existing security controls and incident response capabilities.

Blue team

Focus on Sec Controls

Effectiveness

Tends to be smaller scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Integrated

A

Integrated: Refers to a combination of both offensive and defensive penetration testing.

Purple Team

Continuous assessment

Customized scenarios

Reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly