Practices Used to Secure a Corporate Environment
- "Do I Know This Already?" Quiz
- Foundation Topics
- Exam Preparation Tasks
Securing a corporate environment is not a one-time endeavor. It should entail a set of processes that are embedded into day-to-day operations. Some of these processes, such as penetration testing, are deigned to locate weaknesses before attackers do, while other processes, such as fingerprinting and decomposition, are important to understand because they are techniques that attackers use to thwart your best efforts at preventing the delivery of malware. This chapter discusses the process of penetration testing, the value of understanding how attackers use fingerprinting and decomposition, the importance of training and exercises, and the steps in the risk management process.
“Do I Know This Already?” Quiz
The “Do I Know This Already?” quiz allows you to assess whether you should read the entire chapter. Table 4-1 lists the major headings in this chapter and the “Do I Know This Already?” quiz questions covering the material in those headings so you can assess your knowledge of these specific areas. The answers to the quiz appear in Appendix A, “Answers to the ‘Do I Know This Already?’ Quizzes and Review Questions.” If you miss no more than one of these self-assessment questions, you might want to move ahead to the “Exam Preparation Tasks.”
Table 4-1 “Do I Know This Already?” Foundation Topics Section-to-Question Mapping
Foundation Topics Section |
Questions |
Penetration Testing |
1–3 |
Reverse Engineering |
6 |
Training and Exercises |
4, 5 |
Risk Evaluation |
7 |
Which of the following is the first step in a pen test?
Gather information about attack methods against the target system or device.
Execute attacks against the target system or device to gain user and privileged access.
Document information about the target system or device.
Document the results of the penetration test.
In which type of tests is the testing team provided with limited knowledge of the network systems and device?
Blind test
Double-blind test
Target test
External test
Which of the following is also referred to as a closed, or black-box, test?
Zero-knowledge test
Partial-knowledge test
Full-knowledge test
Target test
Which of the following is not covered in the rules of engagement?
Timing
Scope
Compensation
Authorization
Which of the following acts as the network defense team?
Blue team
White team
Purple team
Red team
With which of the following can malware executable files be executed without allowing the files to interact with the local system?
Sandboxing
DMZ
Trusted Foundry
Decomposition
When performing qualitative risk evaluation, which of the following is considered in addition to the impact of the event?
Attack vectors
Likelihood
Costs
Frequency
