โ† All SAC Flashcard Decks

Assessment & Evaluation Methods Flashcards

7 cards from real SAC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Assessment & Evaluation Methods flashcards as text
  1. What is the key difference between a vulnerability assessment and a penetration test?

    Answer: Vulnerability assessments identify weaknesses; penetration tests actively exploit them

    A vulnerability assessment identifies and reports potential weaknesses, while a penetration test actively attempts to exploit those weaknesses to confirm impact.

  2. In system evaluation, what does SLA compliance measurement track?

    Answer: Whether service levels (uptime, response time) meet contractual commitments

    SLA compliance measurement compares actual service delivery metrics (availability, latency) against contractually defined targets.

  3. Which log source is most useful when evaluating unauthorized privilege escalation attempts on a Linux system?

    Answer: /var/log/auth.log or /var/log/secure

    /var/log/auth.log (Debian/Ubuntu) or /var/log/secure (RHEL/CentOS) records authentication events including sudo and su usage.

  4. What is the purpose of a tabletop exercise in disaster recovery evaluation?

    Answer: Walk stakeholders through a simulated scenario to evaluate response plans

    A tabletop exercise is a discussion-based simulation where participants walk through their roles in a hypothetical disaster to identify gaps in the response plan.

  5. Which assessment methodology uses CVSS scores to prioritize remediation of findings?

    Answer: Risk-based vulnerability management

    Risk-based vulnerability management uses CVSS (Common Vulnerability Scoring System) scores alongside asset criticality to prioritize which vulnerabilities to fix first.

  6. During a configuration assessment, CIS Benchmarks are used primarily to evaluate what?

    Answer: System hardening compliance against security best practices

    CIS Benchmarks provide prescriptive configuration guidelines, and assessments compare system settings against these to measure security hardening.

  7. What does MTTD measure in an IT operations context?

    Answer: Mean Time to Detect an incident or failure

    MTTD (Mean Time to Detect) measures the average time between the start of an incident and when the team becomes aware of it.