Analyzing Vulnerabilities Flashcards

(9 cards)

1
Q

What is Vulnerability Confirmation?

A

Determining the accuracy of identified potential security weaknesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is True Positive?

A

Real and exploitable vulnerability correctly identified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is False Positive?

A

Occurs when the system states that a vulnerability exists on the system, but that vulnerability actually doesn’t exist

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is True Negative?

A

Correctly identifies the absence of a vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is False Negative?

A

Serious finding– vulnerability exists but remains undetected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How are Vulnerabilites prioritized?

A

Factors include ease of exploitation, potential damage, system importance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is CVE (Common Vulnerabilities and Exposures)?

A

A public database that lists known software and hardware vulnerabilities in a standardized way to uniquely identify and reference them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the EF (Exposure Factor)?

A

A quantifiable metric to estimate the percentage of asset damage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is RIsk Tolerance?

A

The level of risk an organization is willing to accept in pursuit of its objectives and before action is deemed necessary to mitigate the risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly