Week 6 (No week 5) - If you have time for Q2 Flashcards

1
Q

What is the purpose of threat identifiers in cybersecurity?

A

To standardize and communicate vulnerability details and threat levels

This allows for international understanding and acceptance within the threat management industry.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does CVE stand for?

A

Common Vulnerabilities and Exposures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the format for CVE identifiers?

A

CVE-YYYY-#### (e.g., CVE-2024-21893)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does NVD stand for and what does it maintain? What does that include?

A

National Vulnerability Database; it maintains a database of CVEs and includes additional information such as analysis and remediation instructions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the difference between CVE and CWE?

A

CVE refers to specific instances of vulnerabilities, while CWE refers to types of software weaknesses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Provide examples of CWE.

A
  • CWE-416: Use After Free
  • CWE-780: Use of RSA Algorithm without OAEP
  • CWE-787: Out-of-bounds Write
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is CAPEC and its focus?

A

Common Attack Pattern Enumeration & Classification; it focuses on application security and exploit techniques.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does CPE stand for and what does it identify?

A

Common Platform Enumeration; it identifies hardware devices, operating systems, and applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is CCE and its purpose?

A

Common Configuration Enumeration; it provides a collection of configuration best practices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the Common Vulnerability Scoring System (CVSS)?

A

A risk management approach to quantify vulnerability data and prioritize response actions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the latest version of CVSS as of November 2023?

A

CVSS v4.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the term ‘Exploit Maturity’ refer to in CVSS?

A

It indicates the maturity of the exploit, categorized as Not Defined, Attacked, Proof-of-Concept, or Unreported.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

True or False: CVSS scores range from 0 to 10.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Fill in the blank: The acronym for the database of Common Vulnerabilities is _______.

A

NVD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly