Security Assessment Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Assessment flashcards as text
What distinguishes a white-box penetration test from a black-box penetration test?
Answer: White-box testers are given full knowledge of the environment; black-box testers receive no prior information
White-box testing provides the tester with full knowledge including source code and architecture, while black-box testing simulates an external attacker with no prior information.
Which document formally authorizes a penetration test and protects the tester from legal liability?
Answer: Authorization to Test / Permission to Attack letter
An Authorization to Test letter (also called Permission to Attack) is signed by an authorized representative and explicitly grants legal permission to conduct the penetration test.
A company wants to assess whether employees follow clean desk and physical security policies. Which assessment technique is most appropriate?
Answer: Physical security walkthrough / inspection
A physical security walkthrough allows assessors to directly observe and document compliance with policies like clean desk, visitor management, and access control.
In the context of security assessments, what does 'pivoting' refer to during a penetration test?
Answer: Using a compromised system as a launching point to attack other internal systems
Pivoting uses an already-compromised host as an intermediary to reach and attack systems in network segments that would otherwise be inaccessible.
Which NIST publication provides a framework for conducting security and privacy risk assessments for federal information systems?
Answer: NIST SP 800-30
NIST SP 800-30 provides guidance for conducting risk assessments, including preparing for, conducting, communicating, and maintaining risk assessment results.
A security assessment reveals that a web server is running an outdated TLS 1.0 configuration. Under CVSS v3.1, which metric would reflect that an attacker must be on the same network segment to exploit this?
Answer: Attack Vector: Adjacent
The CVSS Attack Vector metric 'Adjacent' indicates exploitation requires the attacker to be on the same shared network, such as Bluetooth, RF, or local subnet.
What is the main advantage of using automated vulnerability scanners combined with manual verification during an assessment?
Answer: Manual verification confirms true positives and identifies complex logic flaws scanners miss
Automated scanners efficiently enumerate known vulnerabilities but produce false positives and miss business logic flaws, which manual verification addresses.