Vulnerability And scanners Flashcards
Security Content automation protocol (SCAP)
Allows compatible scanners to determine whether a comp meets configuration baseline.
-uses to accomplish this:
—OVAL
—XCCDF
Open Vulnerability and Assessment Language (OVAL)
XML schema for describing system security state and querying vulnerability reports.
Used by SCAP
Extensible Configuration Checklist Description Format (XCCDF)
XML schema for developing and auditing best-practice configuration checklists and rules.
Uses machine readable format to apply best practices instead of needing to do it manually like previously.
Used by SCAP
Weak Host Configuration
Default settings
Unsecured root accounts
Open permissions
Open ports and services
Unsecure protocols
Weak encryption
Errors