Asset correct answers Something valuable to a company
Reputation, property, data, etc.
Risk correct answers How likely is it that something bad will happen to the asset
Risk = probability * damage potential
Threat correct answers Action that can damage an asset
Threat Actor correct answers The someone or something that can make the threat happen
Vulnerability correct answers Flaws or weaknesses that allow a threat to occur (damage)
Exploit correct answers Taking advantage of a vulnerability
Gain access to things you maybe shouldn't have
Countermeasure correct answers Steps taken to avoid or mitigate the threat
Or reduce the effect
Black box correct answers any system that cannot be directly observed and easily understood
White box correct answers A test where the tester has an in-depth knowledge of the network and
systems being tested, including network diagrams, IP addresses, and even the source code of
custom applications.
Gray Box correct answers A penetration test where some limited information has been provided
to the tester.
, Types of contracts pen-testers may need to sign correct answers 1. NDA
2. Master Service agreement (MSA)
3. Statement of Work (SOW)
Rules of Engagement (RoE) correct answers must be outlined ahead of time
In writing the guidelines and constraints on the execution of the pentest
Without the rules of engagement could face legal ramifications
pen-testing: what types of tests? correct answers Technical
Administrative
Physical
Compliance (PCI, HIPAA, FISMA)
pen-testing: What scope of action? correct answers Vulnerability assessment
Impact driven pen-testing
pen-testing: What vantage point? correct answers Internal LAN
External
Cloud services
what steps are not in a pen-test? correct answers Depends - what the company says you can and
cannot do
May draw a line at extracting data and so on potentially
They may say no escalation or maintain access
Common Hacking Methodology correct answers Reconnaissance
Scanning and enumeration