Filters
Question type

Study Flashcards

Match the following terms to the appropriate definitions. -A comparison of the present state of a system to its baseline.​


A) asset
B) cyberterrorism
C) hactivist
D) exploit kit
E) computer spy
F) risk
G) threat
H) threat agent
I) vulnerability
J) threat vector

K) C) and F)
L) A) and H)

Correct Answer

verifed

verified

Describe the purpose of a honeypot.

Correct Answer

verifed

verified

A honeypot can also direct an attacker's attention away from legitimate servers. A honeypot encourages attackers to spend their time and energy on the decoy server while distracting their attention from the data on the real server.

Most vulnerability scanners maintain a(n) ____________________ that categorizes and describes the vulnerabilities that it can detect.

Correct Answer

verifed

verified

List four things that a vulnerability scanner can do.

Correct Answer

verifed

verified

Alert when new systems are added to the ...

View Answer

A healthy security posture results from a sound and workable strategy toward managing risks.

A) True
B) False

Correct Answer

verifed

verified

Discuss the purpose of OVAL.

Correct Answer

verifed

verified

OVAL is designed to promote open and pub...

View Answer

A(n) ____________________ box test is one in which some limited information has been provided to the tester.

Correct Answer

verifed

verified

gray

Match the following terms to the appropriate definitions. -​In software development, the process of defining a collection of hardware and software components along with their interfaces in order to create the framework for software development.


A) asset
B) cyberterrorism
C) hactivist
D) exploit kit
E) computer spy
F) risk
G) threat
H) threat agent
I) vulnerability
J) threat vector

K) A) and B)
L) H) and I)

Correct Answer

verifed

verified

The first step in a vulnerability assessment is to determine the assets that need to be protected.

A) True
B) False

Correct Answer

verifed

verified

List and describe the three categories that TCP/IP divides port numbers into.

Correct Answer

verifed

verified

Well-known port numbers (0-1023). Reserv...

View Answer

When using a black box test, many testers use ____________________ tricks to learn about the network infrastructure from inside employees.

Correct Answer

verifed

verified

A port scanner can be used to search a system for port vulnerabilities. The RADMIN port scanner is an example of this type of software.

A) True
B) False

Correct Answer

verifed

verified

True

What is the name of the process that takes a snapshot of the current security of an organization?


A) threat analysis
B) vulnerability appraisal
C) risk assessment
D) threat assessment

E) All of the above
F) B) and C)

Correct Answer

verifed

verified

An administrator needs to view packets and decode and analyze their contents. What type of application should the administrator use?


A) application analyzer
B) protocol analyzer
C) threat profiler
D) system analyzer

E) B) and D)
F) A) and B)

Correct Answer

verifed

verified

Discuss one type of asset that an organization might have.

Correct Answer

verifed

verified

An organization has many different types...

View Answer

Match the following terms to the appropriate definitions. -In software development, presenting the code to multiple reviewers in order to reach agreement about its security.​


A) asset
B) cyberterrorism
C) hactivist
D) exploit kit
E) computer spy
F) risk
G) threat
H) threat agent
I) vulnerability
J) threat vector

K) B) and H)
L) C) and F)

Correct Answer

verifed

verified

Match the following terms to the appropriate definitions. -​A computer typically located in an area with limited security and loaded with software and data files that appear to be authentic, but are actually imitations of real data files, to trick attackers into revealing their attack techniques.


A) asset
B) cyberterrorism
C) hactivist
D) exploit kit
E) computer spy
F) risk
G) threat
H) threat agent
I) vulnerability
J) threat vector

K) F) and G)
L) C) and E)

Correct Answer

verifed

verified

What is the end result of a penetration test?


A) penetration test profile
B) penetration test report
C) penetration test system
D) penetration test view

E) All of the above
F) B) and C)

Correct Answer

verifed

verified

​What term below describes a prearranged purchase or sale agreement between a government agency and a business?


A) ​Service Level Agreement (SLA)
B) ​Memorandum of Understanding (MOU)
C) ​Blanket Purchase Agreement (BPA)
D) ​Interconnection Security Agreement (ISA)

E) A) and D)
F) B) and C)

Correct Answer

verifed

verified

If TCP port 20 is open, then an attacker can assume that FTP is being used.

A) True
B) False

Correct Answer

verifed

verified

Showing 1 - 20 of 50

Related Exams

Show Answer