CSS Vulnerability Management & Penetration Testing Flashcards
6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CSS Vulnerability Management & Penetration Testing flashcards as text
What is the primary purpose of a bug bounty program?
Answer: Incentivizes security researchers to responsibly disclose vulnerabilities in exchange for rewards
Bug bounty programs leverage the broader security research community to identify vulnerabilities that internal teams might miss, creating a responsible disclosure channel.
Which type of penetration test is conducted without any prior knowledge of the target environment?
Answer: Black-box testing
Black-box testing simulates an external attacker with no insider knowledge, testing the organization's defenses from the attacker's perspective.
What is the OWASP Top 10 used for in application security?
Answer: A regularly updated list of the most critical web application security risks
The OWASP Top 10 documents the most prevalent and impactful web application vulnerabilities, serving as a baseline for secure development and security testing.
What is the risk-based approach to vulnerability prioritization?
Answer: Prioritizes remediation based on the combination of vulnerability severity, asset criticality, and exploitability
Risk-based prioritization considers not just CVSS score but also how critical the affected asset is and whether active exploits exist, ensuring limited resources focus on the highest-risk items first.
Which tool is commonly used by penetration testers for network discovery and security auditing?
Answer: Nmap (Network Mapper)
Nmap is a widely used open-source tool for network discovery that identifies live hosts, open ports, services, and operating system details.
What is vulnerability chaining in the context of penetration testing?
Answer: Combining multiple lower-severity vulnerabilities to achieve a higher-impact attack outcome
Vulnerability chaining exploits multiple weaknesses in sequence — none of which individually would allow a critical breach — to achieve a high-impact result such as remote code execution.