First step in a pen test
What is to document information about a target system or device.
CIA
What is Confidentiality, Integrity, Availability
A team that acts as the attacking force.
What is Red team?
Categories or risks (DAILY DOUBLE)
What are High, medium, and low?
Most popular social media site/app
What is Facebook?
Type of tests when a testing team is provided with limited knowledge of the network systems and device
What is a Blind test?
NIST
What is the National Institute of Standards and Technology
Acts as the network defense team
What is the blue team?
Policies, procedures, and work practices that help or prevent a threat or make a threat more likely.
What are operational controls?
Kanye West real name
Who is Kanye West?
Rules that define how penetration testing should occur (DAILY DOUBLE)
What are rules of engagement?
OWASP
What is the Open Web Application Security Project, a non-profit organization that focuses on secure web application development.
Group of technicians who referee the encounter between the Red Team and the blue team.
What is the White team?
Controls implemented with technology and include items such as firewalls,access lists, permissions on files or folders, and devices that identify and prevent threats.
What are technical controls?
He is an average kid that no one understands.(pink hat)
Who is Timmy Turner?
A testing team that is provided no knowledge regarding an organizations network, also known as a closed, or black box, testing.
What is a Zero-Knowledge test
ARO
What is the annual rate of occurrence, how many times per year a given loss is expected to occur.
Places malware where it is safe to probe it and play with it
Sandboxing
In addition to the impact of the event when performing qualitative risk evaluation.
What is Likelihood?
The creator of Amazon.
Who is Jeff Bezos?
Testing team provided with public knowledge regarding the organization's network.
What is a Partial-Knowledge test?
PII
What is personally identifiable information, uniquely identifies an individual, such as address, phone number, email, date of birth, etc.
Taking a large document or file and with use of a hashing algorithm, reducing the file to a character string that can be used to verify the integrity of the file.
What is Hashing?
Helps prioritize the application of resources to the most critical vulnerabilities
What is Risk assessment matrix?
Someone in this LC who is afraid of frogs
Who is Cameron?