Test Prep Flashcards

1
Q

Directory Traversal

A

Aims to access files and directories stored outside the webroot folder.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

ARP Poisoning

A

This involves

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Smurf

A

Uses a single ping with a spoofed address sent to the broadcast address of a network. This causes every device in the network to receive a single ping, each device responds to the spoofed address causing the victim to be overwhelmed with the responses to the ping.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Passive information gathering

A

penetration tester gathers publicly available info without the organization being aware that the info was accessed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Active information gathering

A

Starts top probe the organization using port scanning, vulnerability scanning etc that the organization can recognize.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Ping of Death

A

Involves sending a malicious ping to a computer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

MITRE ATT&CK framework

A

provides explicit examples for detecting or mitigating a given threat within a network and ties specific behaviors back to individual actors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

OpenIOC

A

Contains a depth of research on APTs but doesnt integrate the detection and mitigation strategy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Diamond Model of Intrusion Analysis

A

Provides a graphical depiction of the attackers approach relative to kill chain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Cain and Abel

A

Password cracking tool, also includes password decoding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly