Vulnerability Scanners and Penetration Testing Flashcards

1
Q

What is a vulnerability scanner?

A

It is software that scans a network and does a vulnerability analysis and grades vulnerability schedules according to CVSS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is CVSS?

A

Common Vulnerability Scoring System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the shortcomings of vulnerability scanners?

A

It lacks the dynamic context of the network. Doens’t see misconfigurations or human factor.

You can see a lot, but it doesn’t actually lead you anywhere. So a ton of false positives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a penetration test?

A

Dynamic evaluation of security controls, as well as business impact of vulnerabilities across the network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does a penetration tester do?

A

Starts by operating vulnerability scanner, deals with exploitable vulnerabilites, then tries to exploit in order to prove the actual business impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the pains of human penetration testing? (There are 6)

A
  1. There is a shortage of cybersecurity professionals, so very expensive.
  2. Pentester will find an achievement but not all possible attack vectors leading to it. So not everything is mapped.
  3. Talent dependent, vast differences between quality of pentesters.
  4. Consumes a lot of valuable in house resources. If you’re bringing in a third party, it’s a whole project.
  5. Just a snapshot in time, new vulnerabilities come up in infrastructure all the time.
  6. Reports are cryptic, just provides samples, only reports on successes, doesn’t give you effective remediation.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly