Discovering & Analyzing Vulnerabilities Flashcards

(13 cards)

1
Q

Is Nikto open source?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does Nikto do?

A

Web server vulnerability scanner and checks for configuration errors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is TruffleHog?

A

tool for scanning code repositories, clooud storage and other sources to detect exposed secrets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

TruffleHog can be integrated into what?

A

CI/CD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Is Grype open source?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does Grype do?

A

Vulnerability scanner for container images

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Grype can scan what?

A

Containers and file systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Kube-hunter is for what?

A

Kubernetes scanning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Greenbone OpenVAS for?

A

full features vulnerability scanner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is BllodhoundAS/Sharphound for?

A

mapping out Active Directory environments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is PingCastle for?

A

assessesthe security health of an Active Directory environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Auto jigglers are used to overcome what type of locks?

A

Waffer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Bump keys are used to ovecome which locks

A

pin tumbler locks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly