Save
Upgrade to remove ads
Busy. Please wait.
Log in with Clever
or

show password
Forgot Password?

Don't have an account?  Sign up 
Sign up using Clever
or

Username is available taken
show password


Make sure to remember your password. If you forget it there is no way for StudyStack to send you a reset link. You would need to create a new account.
Your email address is only used to allow you to reset your password. See our Privacy Policy and Terms of Service.


Already a StudyStack user? Log In

Reset Password
Enter the associated with your account, and we'll email you a link to reset your password.
focusNode
Didn't know it?
click below
 
Knew it?
click below
Don't Know
Remaining cards (0)
Know
0:00
Embed Code - If you would like this activity on your web page, copy the script below and paste it into your web page.

  Normal Size     Small Size show me how

Vulnerability manage

Vulnerability management

QuestionAnswer
Identifying vulnerabilities Systematic practice of spotting and categorizing weaknesses in a system, network, or application that could potentially be exploited
Vulnerability scanning Automated method of probing networks, systems, an application to discover potential vulnerabilities
Application security Used to safeguard the software from being manipulated during its life cycle
Static analysis Used to analyze an application's source code without executing it
Dynamic analysis Evaluate an application as it is being run to determine if there are any vulnerabilities in the application
Package monitoring Ensures that the libraries and components that the application depends on our secure and up-to-date
Penetration testing Used to simulate a real world attack on a system to evaluate it security posture
system and process audits Process that involves conducting a comprehensive review of the information systems, security policies, and procedures
Identifying vulnerabilities Systematic practice of spotting and categorizing weaknesses in a system, network, or application that could potentially be exploited
Threat intelligence Continue process used to understand the threats faced by an organization
threat intelligence feed Continuous stream of data related to potential or current threats to an organization security
Open source intelligence (OSINT) Intelligence that is collected from publicly available sources including reports, forms, news articles, blogs, and social media posts
proprietary or third-party feeds Threat intelligence feeds that are provided by commercial vendors, usually under a subscription service type of business model
dark web Part of the Internet that is intentionally hidden and inaccessible through standard web browsers
responsible disclosure Term used to describe the ethical practice where a security researcher discloses information about vulnerabilities in a software, hardware, or online service
common vulnerabilities and exposures (CVE) System that provides a standardized way to uniquely identified in reference known vulnerabilities and software and hardware
healthcare vulnerabilities Risk patient data and safety
Financial institution vulnerabilities Lead to monetary losses and regulatory scrutiny
exposure factors (EF) Used as a quantifiable metric to help a cybersecurity professional understand the exact percentage of an asset that is likely to be damaged or affected if a particular vulnerability is exploited
Risk tolerance Refers to the level of risk that an organization is willing to accept in pursuit of its objectives and before action is the necessary to mitigate the risk
vulnerability response and remediation Strategies that identify, assess, and address vulnerabilities in a system or network to strengthen an organizations security posture
Patching Applying Software Update updates to fix security vulnerabilities
purchasing cyber security insurance policies Procuring insurance policies to mitigate financial losses from cyber incidents
network segmentation Dividing a network into smaller segments for improved security and performance
Implementing compensating controls Alternative security measures is used for situations where standard controls are not feasible or effective
exception Temporarily relaxes security controls for operational business needs
Exemption Permanently waves controls for specific reasons, such as when using a legacy system
configuration auditing Checks for misconfigurations
patch auditing Verifies proper patch application
vulnerability reporting Process of documenting and communicating details about security weaknesses identified in software or systems to the individuals or organizations responsible for addressing the issue
internal reporting Involve identification, documentation, and communication of the organizations vulnerabilities within the organizational structure of the organization
External reporting Involves discussions with the vendors, partners, customers, or the Public at large, depending on the specific vulnerability involved
responsible disclosure reporting art of disclosing vulnerabilities ethically and judiciously to the affected stakeholders before making the announcement to the Public at large
System monitoring Observation of computer system, including the utilization and consumption of its resources.
baseline Established performance metrics and data points for standard behavior of a system, network, or application
Application monitoring Emphasizes the management and monitoring of software Application performance and availability.
infrastructure monitoring Observation of the performance and availability of an organization's physical and virtual infrastructure
Log aggregation Process of collecting and consolidating log data from various sources into a centralized location
alerting Involves setting up notifications to inform relevant stakeholders when specific events or conditions occurred
scanning Involves examining systems, networks, or applications to identify vulnerabilities, configuration issues, or other potential problems
vulnerability scan Checks for vulnerabilities in systems, networks, or applications by comparing the system's state against databases of vulnerabilities
configuration scan Checks for misconfigurations that could impact system performance or security
code scan Checks the source code of an application for potential issues, such as security vulnerabilities or coding errors
reporting Involves generating summaries or detailed reports based on the collected and analyzed data
archiving Involves storing data for long-term retention and future reference, including organizations log data, performance data, and incident data
alert response and remediation or validation Involves taking appropriate actions in response to alert alerts and ensuring that the identified issues have been effectively addressed
quarantining Isolating a system, network, or application to prevent the spread of a threat and limit its potential impact
alert tuning Adjusting alert parameters to reduce errors, false positives, and to improve the overall relevance of the alerts being generated by a given system
simple network management protocol (SNMP) Internet protocol for collecting and organizing information about managed devices on IP networks and from modifying the information to change device behavior
Granular Sent trap messages get a unique objective identifier to distinguish each message as a unique message being received
management information base (MIB) Used to describe the structure of the management data of a device subsystem using a hierarchical namespace containing object identifiers
Verbose SNMP traps may be configured to contain all the information about a given alert or event as a payload
SIEM Solution that provides real-time or near-real-time analysis of security alerts that are generated by network hardware and applications
Agent Software agent installed on each system, such as a server or workstation, from which SIM needs to collect log data
Agentless Under this approach, the SIEM system directly collects log data from each system using standard protocols such as SNMP or WMI
splunk Market-leading big data information gathering and analysis tool that can import machine-generated data via a connector or a visibility add-on
elastic stack (ELK) Collection of free and open-source SIEM tools that provide storage, search, and analysis functions
ArcSight SIEM log management and analytics software that can be used for compliance reporting for legislation and regulations like HIPAA, SOX, and PCI DSS
QRadar SIEM log management, analytics, and compliance reporting platform created by IBM
security information and event management system (SIEM) The central hub for the consolidation to provide a holistic view of an organization's security landscape
antivirus software Fundamental security tool that protects systems against malware, including viruses, worms, Trojans, ransom, and spyware
Data loss prevention systems Used to monitor and control data endpoints, network traffic, and data stored in the cloud to prevent potential data breaches from occurring
network intrusion detection systems (NIDS) Passively identifies any potential threats
network intrusion prevention systems (NIPS) Actively blocks or prevents these potential threats
firewalls Serve as a barrier between a trusted internal network and an untrusted external network
vulnerability scanners Tools that identify security weaknesses in a system, including missing patches, incorrect configurations, and other types of known vulnerabilities
security content automation protocol (SCAP) Open standards that automate vulnerability management, measurement, and policy compliance for systems in an organization
Open vulnerability and assessment language (OVAL) XML schema for describing system security states and querying vulnerability reports and information
extensible configuration checklist description format (XCCDF) XML schema for developing and auditing best-practice configuration checklists and rules
asset reporting format (ARF) XML schema for expressing information about assets and the relationships between assets and reports
common configuration enumeration (CCE) Scheme for provisioning secure configuration checks across multiple sources
common platform enumeration (CPE) Scheme for identifying hardware devices, operating system systems, and applications
common vulnerabilities and exposures (CVE) List of records where each item contains a unique identifier used to describe a publicly known vulnerability
common vulnerability scoring system (CVSS) Used to provide a numerical score to reflect the severity of a given vulnerability
0 = None
0.1 - 3.9 = Low
7.0 - 8.9 = High
9.0 - 10.0 = critical
benchmark Set of security configuration rules for some specific set of products to provide a detailed checklist that can be used to secure systems to a specific baseline
full packet capture (FPC) Captures the entire packet, including the header and the payload for all traffic entering and leaving a network
Flow analysis Relies on a flow collector, which records Metadata and statistics rather than recording each frame that passes through the network
NetFlow A Cisco-developed means of reporting network flow info to a structured database
IP flow information export (IPFIX) Defines traffic flows based on shared packet characteristics
Zeek Passively monitors a network like a sniffer, but only logs full packet capture data of potential interest
Multi router traffic grapher (MRTG) Creates graphs showing traffic flows through the network interfaces of routers and switches by polling the appliances using SNMP
Single pane of glass A central point of access for all the information, tools, and systems
defining the requirements Involves Identifying the information, tools, and systems
identifying and integrating data sources Involves identifying the data sources that the security team needs to access
customizing the interface Involves designing the user interface and configuring panels and views to display information and data
developing standard operating procedures and documentation Ensures that the security teams know how to use the single paint of glass and understand the process and procedures
Continuously monitoring and maintaining the solution Include regular reviewing of the data and information
Created by: user-2044395
 

 



Voices

Use these flashcards to help memorize information. Look at the large card and try to recall what is on the other side. Then click the card to flip it. If you knew the answer, click the green Know box. Otherwise, click the red Don't know box.

When you've placed seven or more cards in the Don't know box, click "retry" to try those cards again.

If you've accidentally put the card in the wrong box, just click on the card to take it out of the box.

You can also use your keyboard to move the cards as follows:

If you are logged in to your account, this website will remember which cards you know and don't know so that they are in the same box the next time you log in.

When you need a break, try one of the other activities listed below the flashcards like Matching, Snowman, or Hungry Bug. Although it may feel like you're playing a game, your brain is still making more connections with the information to help you out.

To see how well you know the information, try the Quiz or Test activity.

Pass complete!
"Know" box contains:
Time elapsed:
Retries:
restart all cards