5.5 - CompTIA Security+

0.0(0)
studied byStudied by 0 people
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/11

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

12 Terms

1
New cards

Attestation

The opinion of truth/conclusion that is associated with an audit.

2
New cards

Audit committee

A group responsible for all of the risk management associated with an organization, and for starting/stopping any internal audits.

3
New cards

Self-assessments

Allows an organization to review its internal processes and procedures to see how well they match organizational requirements.

4
New cards

Physical penetration test

A pentest involving attackers attempting to gain access to the physical facility/devices.

5
New cards

Offensive penetration test

A test designed to evaluate the effectiveness of security controls against unauthorized access, simulating real-world attacks to identify vulnerabilities.

6
New cards

Defensive penetration test

Refers to the defensive/blue team identifying incoming attacks in real time and blocking them.

7
New cards

Integrated penetration test

A holistic approach combining various penetration testing methodologies to evaluate an organization's security operations.

8
New cards

Known environment pentesting

A penetration test where the tester has detailed knowledge about the target system or network.

9
New cards

Partially known environment pentesting

A penetration test where the attacker has limited knowledge about the target system or network and uses reconnaissance techniques to gather information.

10
New cards

Unknown environment pentesting

A penetration test where the tester has little prior knowledge about the target system or network, mimicking an attack from an unknown entity.

11
New cards

Passive reconnaissance

Penetration testing techniques that do not interact directly with target systems (e.g., OSINT, network traffic monitoring).

12
New cards

Active reconnaissance

Penetration testing techniques that interact directly with target systems (e.g., port scanning, DNS enumeration).