Testing Frameworks & Methodologies Flashcards

(26 cards)

1
Q

OSSTMM stands for

A

Open Source Security Testing Methodology Manual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

OSSTMM has what structured stages

A
  1. Testing
  2. Analysis
  3. Measurement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Rav stands for?

A

Risk Assessment Value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the Primary Matrices of the MITRE ATT&CK Framework?

A

Enterprise Matrix
Mobile Matrix
Industrial COntrol System (ISC) Matrix

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Key Components of the MITRE ATT&CK Framework are:

A
  1. Reconnaissance
  2. Resource development
  3. Initial access
  4. Execution
  5. Persistence
  6. Privilege esclation
  7. Defense evasion
  8. Credential access
  9. Discovery
  10. Lateral movement
  11. Collection
  12. Command and control
  13. Exfiltration
  14. Impact
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the OWASP Top 10:

A

A01:2021 - Broken Access Control
A02:2021 - Cryptographic Failures
A03:2021 - Injection
A04:2021 - Insure Design
A05:2021 - Security Misconfiguration
A06:2021 - Vunerable and Outdates Components
A07:2021 - Identification and Authentication Failures
A08:2021 - Software and Data Integruity Failures
A09:2021 - Security Logging and Monitoring Failures
A10:2021 - Server-Side REquest Forgery (SSRF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

MASVS stand for

A

OWASP Mobile Application Security Verification Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The Purdue Model is part of what?

A

Purdue Enterprise Reference Architecture (PERA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The Purdure Model protects what?

A

Operational Technologies (OT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The Purdue Model divides the ICS architecture into how many zones?

A

6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the Purdue Model zones?

A

Level 4/5 - Enterprise
DMZ
Level 3 - Operation & Control
Level 2 - Control
Level 1 - Process
Level 0 - Process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

CREST stands for

A

Council of Registered Ethical Security Testers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

PTES stands for

A

Penetration Testing Execution Standard.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The steps in the PTES are:

A
  1. Pre-engagement interactions
  2. Threat modeling
  3. Intelligence gathering
  4. Vulnerability analysis
  5. Exploitation
  6. Post-exploitation
  7. Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ISSAF stands for

A

Information System Security Assessment Framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ISSAF is no longer supported, it has the following phases:

A
  1. Planning and Preparation
  2. Assessment
  3. Reporting, Clean up and destroy artifacts
17
Q

DREAD Threat model Framework was made by Microsoft and stand for:

A

Damage Potential
Reproducibility
Exploitability
Affected users
Discoverability

18
Q

STRIDE Threat Modeling Framework stands for

A

Spoofing
Tampering
Repudiation
Information disclosure
Denial of service
Elevation of privilege

19
Q

STRIDE is used to for

A

Threat modeling

20
Q

OCTAVE Threat Modeling Framework stand for:

A

Operationally critial threat asses and vulnerability evaluation

21
Q

OCTAVE-S is for

A

small organisations

22
Q

OCTAVE Allegro does what

A

simplifies the risk assessment process

23
Q

OCTAVE Forte is a

A

highly adapatable variation

24
Q

CVE Stands for

A

common vulnerabilities and exposures

25
CWE stands for:
common weakness enumerations
26
CAPEC stands for
Common attack Pattern Enumerations and classifications