Software Testing Versus Website Vulnerability and Security Assessments

0.0(0)
studied byStudied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/12

flashcard set

Earn XP

Description and Tags

These flashcards cover key concepts related to software testing, website vulnerability, and security assessments from the lecture notes.

Last updated 2:36 PM on 2/3/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

13 Terms

1
New cards

What is a primary difference between software testing and website security assessments?

Software testing is a broader set of procedures, while website security assessments focus specifically on security vulnerabilities.

2
New cards

What are the four elements that typically make up a website?

  1. Web server software 2. A hardware server and operating system 3. A software application 4. A database

3
New cards

What is the purpose of performing an initial discovery on a targeted website?

To identify components of the website platform that need to be tested or attacked.

4
New cards

What is a ping sweep?

A method of using the ping utility across a range of IP addresses to identify active hosts.

5
New cards

What is the Nmap utility primarily used for?

Network mapping, including ping sweeping, port scanning, and operating system detection.

6
New cards

How can operating system fingerprinting help in security assessments?

It helps in identifying the OS to determine tools and techniques for further assessment.

7
New cards

What is Nessus?

A popular vulnerability scanning tool that tests systems for vulnerabilities and compliance.

8
New cards

What is cross-site scripting (XSS)?

A vulnerability that allows attackers to inject scripts into web pages viewed by other users.

9
New cards

What does PCI DSS stand for?

Payment Card Industry Data Security Standards, which are security standards for organizations that handle credit cards.

10
New cards

What is penetration testing?

A method of testing a system's security by simulating an attack to identify vulnerabilities.

11
New cards

What is one of the main parts of a vulnerability assessment report?

An executive summary presenting the key findings and recommendations.

12
New cards

Why is it advisable to use multiple tools for security assessments?

Different tools may detect different vulnerabilities, providing a more comprehensive assessment.

13
New cards

What is the significance of distinguishing between authenticated and unauthenticated scans?

Authenticated tests provide a complete view of security risks, while unauthenticated scans may miss certain vulnerabilities.