Security Operations: Examining Vulnerability Analysis Flashcards

1
Q

What are False Positives and Negatives?

A

False positives and negatives

The difference between false positives and negatives is that:

False positives are indicators or alerts of the presence of vulnerabilities that don’t actually exist. They can cause unnecessary interruptions, administrative overhead, and alert fatigue.

False negatives are vulnerabilities that are realized but are marked as nonexistent. This gives a false sense of security, as an asset can lack proper security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is CVE?

A

Common Vulnerability Exposure

CVE is a public list of vulnerabilities, and:

Each vulnerability is assigned a CVE identification number.

This list is used in other databases, such as the U.S. National Vulnerability Database (NVD).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is CVSS?

A

Common Vulnerability Scoring System

CVSS is a method used to supply a qualitative measure of severity. CVSS metric groups include:

Base: The most rudimentary, immutable qualities of a vulnerability.

Temporal: The time-dependent qualities of a vulnerability.

Environmental, or environmental variables: The implementation and environment-specific qualities of a vulnerability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How can you utilize CVE and CVSS?

A

When you have these vulnerability references, you can utilize them for:

Classification.

Prioritization:

Industry and organizational impact: Enables asset classification and valuation and business-impact analysis (BIA).

Exposure factor: Specifies percentage of asset value that would be lost, if a threat is realized.

Remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly