Sybex Chapter 2 - Planning and Scoping Penetration Tests Flashcards

1
Q

what is a “white box” or “crystal box” test?

A

Known environment OR Full Knowledge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does ATT&CK stand for in MITRE ATT&CK Framework?

A

Adversarial Tactics, Techniques, and Common Knowledge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

OWASP

A

Open Web Application Security Project: testing guides for web security, mobile security, firmware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

PTES

A

Penetration Testing Execution Standard: pre-engagement interactions like scoping and client questions; testing techniques and concepts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

OSSTMM

A

Open Source Security Testing Methodology Manual: broad penetration testing methodology guide. Not updated since 2010

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

NIST

A

National Institute of Standards and Technology: provides standards and cybersecurity frameworks that includes penetration testing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ISSAF

A

Information Systems Security Assessment Framework: highly detailed pen testing framework, but not updated since 2005

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SOW

A

Statement of Work

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

SOO

A

Statement of Objective; alternative to SOW. Used by US gov

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

PSW

A

Performance Work Statement: used by US gov; alternative to SOW

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

MSA

A

Master Service Agreement: defines terms the orgs will use for future work. Prevents the need to renegotiate terms at every SOW

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

CA

A

Confidentiality Agreement. Like NDA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

GLBA

A

Gramm-Leach-Bliley Act: complies regarding how financial institutions manage personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

FIPS 140-2 -> FIPS 140-3

A

US Gov computer security standard to approve cryptographic modules. Crypto modules can be FIPS 140-2 certified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly