Vulnerability Management
Tools of the Trade
Compliance
Frameworks
MISC
100

Common scoring system used to rate vulnerabilities.

CVSS

100

Tool used for OSINT gathering

Recon-NG

100

Organizations handling credit card transactions must comply with this comprehensive, worldwide security standard established by a council of major payment networks.

PCI DSS (Payment Card Industry Data Security Standard)

100

The FIRST action in IR after identifying malware on a critical server.

Containment

100

Which tool is BEST suited for log aggregation and correlation?

SIEM

200

This vulnerability scanner developed by Tenable uses plugins to identify known vulnerabilities

Nessus

200

Packet capture tool frequently used for network analysis on command line


TCP dump

200

This Framework focuses on Web Application Security

OWASP

200

Analysts remove malware, reset passwords, and delete persistence mechanisms. What phase of IR is this?

Eradication

200

An internal team hires an external firm to run an assessment where the penetration testers are provided zero pre-existing documentation, structural maps, or source code blueprints, mirroring an outside adversarial scenario.

Black Box testing


300

A numerical representation of how difficult a vulnerability is to exploit (CVSS)

Attack Complexity 

300

Tool commonly used for port scanning and enumeration.

Nmap

300

This framework associates with Information Security Management

ISO 27000

300

A threat actor known as APT32 launches a campaign. What diamond model component does APT 32 represent?

Adversary

300

An attacker creates malware before sending it to the victim. What phase is this in the Cyber Kill Chain?

Weaponization

400

The process of eliminating a risk entirely by removing the vulnerable asset or activity.

Risk avoidance

400

Framework often used for exploitation during penetration testing for cloud environment

Pacu

400

the principle that children under 13 cannot legally consent to having their digital footprints tracked, profile-built, or commercialized.  

COPPA

400

Which Kill Chain phase should defenders stop to prevent malware from reaching users?

Delivery

400

A web application receives the following request: https://company.com/page.ph?pfile=../../../../etc/passwd

What attack is being attempted?


Directory Traversal


500

A vulnerability scanner reports CVE-XXXX on a server. An analyst manually verifies the service version and discovers the server is not vulnerable.

False Positive

500

Threat intelligence platform used to map relationships between entities.

Maltego

500

This document is formal proof that an organization meets PCI DSS requirements

Attestation of Compliance (AOC)

500

The malware has been installed but has not yet communicated externally.

Which phase has NOT occurred yet in the Cyber Kill Chain?

Command and Control (C2)

500

What is the name of the threat intelligence data format.

STIX