Management Questions & Answers5
Risk Management Treatment - ANSWERS-Avoidance
Reduction
Transfer
Acceptance
Risk Types - ANSWERS-Inherent Risk
Residual Risk
Inherent Risk - ANSWERS-The ammount of risk that exists in the absense of controls
Residual Risk - ANSWERS-The ammount of risk that remains after controls are accounted for
Risk Calculation - ANSWERS-Likelehood of a threat
Impact from the threat
Remediation time
ALE - ANSWERS-Annual Loss Expectancy
SLE - ANSWERS-Single Loss Expectancy
ARO - ANSWERS-Annualised Rate of Occurrence
, Engagement Lifecycle - ANSWERS-Pre-Engagement
Reconnaissance
Scanning & Enumeration
Exploitation
Post Exploitation
Reporting
Debrief
Non-Disclosure Agreement - ANSWERS-The first thing to be signed
Assures client that information will not be disclosed.
Pre-Engagement Phase - ANSWERS-Rules of Engagement
Objective and Scope
Timeline and Milestones
Liabilities / Responsibilities
Allowed Techniques
Deliverables / Expectations
Pentest Objective - ANSWERS-Why do the company want a Penetration Test
Scope of Engagement - ANSWERS-What is allowed to be tested
Defines Boundaries
Black Box / Grey Box / White Box / Red Team
Black Box Testing - ANSWERS-No information
Simulates external attacks without prior knowledge