D484 - QUESTIONS AND
CORRECT DETAILED
ANSWERS (VERIFIED
ANSWERS) ALREADY
GRADED A+
When using a structured
approach to PenTesting, each step Planning and scopin
will serve a purpose with the goal J PIng
of testing an infrastructure's Information gathering and
defenses by identifying and . vulnerability scanning
exploiting any known ' Attacks and exploits
vulnerabilities. List the four main | icati
steps of the CompTIA Pen Testing
' R eporti'ng and communication
process.
Threat actors follow the same 1) Planning and scoping along
main process of hacking as a . with 3) Analysis and reporting.
professional PenTester:
Reconnaissance, Scanning, Gain
Access, Maintain Access, and
,Cover Tracks. What steps are
added during a structured
PenTest?
Payment Card Industry Data
. Security Standard (PCI DSS)
. specifies the controls that must
Part of completing a PenTesting
be in place to securely handle
exercise is following the imposed
. credit card data. Controls include
guidelines of various controls,
: .| methods to minimize
laws, and regulations. Summarize | -y
. vulnerabilities, employ strong
Key takeaways of PCI DSS.
: access control, along with
consistently testing and
: monitoring the infrastructure.
With PCI DSS a merchant is
ranked according to the number . A Level 1 merchantis a large
of transactions completed in a i merchant with over six million
year. Describe a Level 1 . transactions a year.
merchant.
With PCI DSS, a Level 1 merchant
must have an external auditor . Qualified Security Assessor
perform the assessment by an | (QSA).
approved
Another regulation that affects Require consent means a
data privacy is GDPR, which i company must obtain your
outlines specific requirements on | permission to share your
how consumer data is protected. information.
List two to three components of
i Rescind consent allows a
GDPR.
consumer to opt out at any time.
, Global reach—GDPR affects
. anyone who does business with
residents of the EU and Britain.
. Restrict data collection to only
. what is needed to interact with
| the site.
. Violation reporting—a company
must report a data breach within
i 72 hours.
. Under GDPR, any company with
over 250 employees will need to
What should a company with i audit their systems and take
over 250 employees do to be rigorous steps to protect any data
compliant with the GDPR? : that is processed within their
systems, either locally managed
. or in the cloud.
. NIST has many resources for the
cybersecurity professional that
Describe some of the resources include the Special Publication
available at NIST. 800 series, that deals with cyber
security policies, procedures, and
. guidelines.
NIST SP 800-115 is the "Technical
: Guide to Information Security
. Testing and Assessment" and
Discuss the significance of NIST
contains a great deal of relevant
SP 800-115.
. information about PenTesting
planning, techniques, and related
: activities.
, : Once in the MITRE ATT&(CK
Explain how the MITRE ATT&CK . framework, you will see many
Framework provides tools and . columns in the matrix that
techniques specific to PenTesting. describe various tasks that are
completed during the PenTest.
The CWE is a dictionary of
. software-related vulnerabilities
: maintained by the MITRE
Compare and contrast CVE and Corporation that includes a
CWE. . detailed list of weaknesses in
. hardware and software. CVE
refers to specific vulnerabilities of
: particular products.
A couple of your colleagues
The team will need to clearly
thought it might be a good idea
. understand that they are to
to share some guidance on how
maintain confidentiality before,
the team should conduct
themselves during the PenTesting durlng, and after 2 Pen.Test .
. exercise. Once the testing begins
process. What topics should be
the team will want to proceed
covered so that all members
. with care and notify the team
exhibit professional behavior
lead if they have observed any
before, during and after the
: illegal behavior.
PenTest?
The team is involved with . Who will notify security
planning a PenTest exercise for personnel that the team is using a
515support.com. Management is : social engineering exercise to
concerned that the loading dock gain access into the building?
is vulnerable to a social
How many individuals should be
engineering attack, whereby
: testing to see if this type of
someone can gain access to the
. exploit is possible?