Sybex Chapter 1 - Penetration Testing Flashcards
1
Q
D.A.D. Triad
A
Disclosure, Alteration, Denial. The antithesis to the CIA triad, Confidentiality, Integrity, Availability
2
Q
SIEM
A
Security Information and Event Management
3
Q
Threat Hunting
A
Search an org’s infrastructure in search of signs of a successful attack
4
Q
PCI DSS
A
Payment Card Industry Data Security Standard
5
Q
CDE
A
Cardholder Data Environment (How PCI DSS refers to card processing environments)
6
Q
CompTIA PenTesting Process
A
1) Planning and Scoping
2) Information Gathering and Vuln Scanning
3) Attacking and Exploiting
4) Reporting and Communicating Results
7
Q
The Cyber Kill Chain
A
1) Reconnaissance
2) Weaponization
3) Delivery
4) Exploitation
5) Installation
6) Command & Control
7) Actions on Objectives