Security Assessment Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Assessment flashcards as text
A penetration tester successfully gains domain administrator privileges during an internal test. What should be the tester's immediate next step?
Answer: Document the finding, notify the client per the rules of engagement, and await guidance
Upon achieving a significant objective like domain admin, testers must document findings immediately and notify the client per agreed-upon escalation procedures in the rules of engagement.
Which threat modeling methodology uses an attacker-centric approach organized around four categories: Goals, Observations, Plan, and Actions?
Answer: PASTA
PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling framework that aligns attacker motivations with business objectives across seven stages.
During an assessment, a tester intercepts network traffic and finds credentials transmitted in cleartext. Which control failure does this primarily demonstrate?
Answer: Absence of encryption for data in transit
Cleartext credential transmission indicates the absence of transport encryption (such as TLS), which is required to protect data in transit from interception.
What is the purpose of a 'tiger team' in the context of security assessments?
Answer: A group of security experts authorized to conduct aggressive, goal-based offensive testing
A tiger team is a specialized group authorized to conduct adversarial testing using any means necessary to achieve defined objectives, simulating advanced threat actors.
An organization wants to continuously identify new vulnerabilities as systems change rather than relying solely on periodic assessments. Which approach supports this goal?
Answer: Continuous vulnerability management with automated scanning
Continuous vulnerability management uses automated, recurring scans integrated with asset inventory to detect new vulnerabilities as environments evolve.
Which artifact should a penetration test final report always include to help the organization act on findings effectively?
Answer: An executive summary and a prioritized remediation roadmap
A quality penetration test report includes an executive summary for leadership and a technical remediation roadmap prioritized by risk to guide the security team's response.
Which OWASP tool is commonly used during web application security assessments as an intercepting proxy to analyze and manipulate HTTP/HTTPS traffic?
Answer: Burp Suite
Burp Suite is the de facto standard web application security testing proxy used to intercept, inspect, and manipulate HTTP/HTTPS traffic during assessments.