Save
Busy. Please wait.
Log in with Clever
or

show password
Forgot Password?

Don't have an account?  Sign up 
Sign up using Clever
or

Username is available taken
show password


Make sure to remember your password. If you forget it there is no way for StudyStack to send you a reset link. You would need to create a new account.
Your email address is only used to allow you to reset your password. See our Privacy Policy and Terms of Service.


Already a StudyStack user? Log In

Reset Password
Enter the associated with your account, and we'll email you a link to reset your password.
focusNode
Didn't know it?
click below
 
Knew it?
click below
Don't Know
Remaining cards (0)
Know
0:00
Embed Code - If you would like this activity on your web page, copy the script below and paste it into your web page.

  Normal Size     Small Size show me how

Security+ Chapter 5

Security+ Chapter 5 Review Questions

QuestionAnswer
Name five factors that influence how often an organization decides to conduct vulnerability scans against its systems. Risk appetite, regulatory requirements, technical constraints, business constraints, and licensing limitations
Give some examples of controls that might affect scan results. Firewall settings, network segmentation, intrusion detection systems (IDS), and intrusion prevention systems (IPS)
Name all three techniques used by application testing Static testing, dynamic testing, interactive testing
What information does the output section provide on the report? The output section of the report shows the detailed information returned by the remote system when probed for the vulnerability.
What information does the port/hosts section provide on the report? The port/hosts section provides details on the server(s) that contain the vulnerability as well as the specific services on that server that have the vulnerability.
List all eight CVSS metrics attack vector metric, attack complexity metric, privileges required metric, user interaction metric, confidentiality metric, integrity metric, availability metric, and scope metric
Please interpret the following CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N •Attack Vector: Network (score: 0.85)•Attack Complexity: Low (score: 0.77) • Privileges Required: None (score: 0.85) •User Interaction: None (score: 0.85) •Scope: Unchanged• Confidentiality: High (score: 0.56)• Integrity: None •Availability: None
What is the function to calculate the impact sub-score? ISS = 1 – [(1 – Confidentiality) x (1-Integrity) x (1-Availability)]
How do you calculate the impact score for a vulnerability under CVSS? Impact score = the value of the scope metric * ISS
How do you calculate the exploitability score for a vulnerability under CVSS? Exploitability = 8.22 × AttackVector × AttackComplexity × PrivilegesRequired x UserInteraction
Explain true positive, false positive, true negative, and false negative When a vulnerability scanner reports a vulnerability, this is known as a positive report. When a scanner reports that a vulnerability is not present, this is a negative report.
Give three valuable information sources for reconciling scan results. • Log reviews from servers, applications, network devices • Security information and event management systems that correlate log entries from multiple sources and provide actionable intelligence • Configuration management systems
Give some examples of weak configurations • The use of default settings that pose a security risk • The presence of unsecured accounts • Open ports and services • Open permissions that allow users access which violates the principle of least privilege
Name two choices you need to make when you implement encryption. • The algorithm to use to perform encryption and decryption • The encryption key to use with that algorithm
What are the benefits of penetration testing? 1. Penetration testing provides us with knowledge that we can’t obtain elsewhere 2. In the event that attackers are successful, penetration testing provides us with an important blueprint for remediation
What are three typical classifications that are used to describe penetration test types? White box, black box, gray box
Identify four key phases of a penetration test. Initial access, privilege escalation, pivoting (lateral movement), and persistence
Name the three teams that participate in a cybersecurity exercise Red team, blue team, and white team
Created by: musa_husseini
Popular Computers sets

 

 



Voices

Use these flashcards to help memorize information. Look at the large card and try to recall what is on the other side. Then click the card to flip it. If you knew the answer, click the green Know box. Otherwise, click the red Don't know box.

When you've placed seven or more cards in the Don't know box, click "retry" to try those cards again.

If you've accidentally put the card in the wrong box, just click on the card to take it out of the box.

You can also use your keyboard to move the cards as follows:

If you are logged in to your account, this website will remember which cards you know and don't know so that they are in the same box the next time you log in.

When you need a break, try one of the other activities listed below the flashcards like Matching, Snowman, or Hungry Bug. Although it may feel like you're playing a game, your brain is still making more connections with the information to help you out.

To see how well you know the information, try the Quiz or Test activity.

Pass complete!
"Know" box contains:
Time elapsed:
Retries:
restart all cards