QUALYS ACTUAL TEST PAPER COMPLETE
QUESTIONS AND ANSWERS FULL
SOLUTION
●● tcpdump
Answer: a command-line packet sniffing utility
●● Endpoint Detection and Response (EDR)
Answer: A software agent that collects system data and logs for analysis
by a monitoring system to provide early detection of threats
●● Sandboxing
Answer: Computing environment that is isolated from a host system to
guarantee that the environment runs in a controlled, secure fashion.
Communication links between the sandbox and the host are usually
completely prohibited so that malware or faulty software can be
analyzed in isolation and without risk to the host.
●● AbuseIPDB
Answer: a popular website used to check for IP addresses associated
with malicious activity
●● kill chain
, Answer: a model developed by Lockheed Martin that describes the
stages by which a threat actor progresses to a network intrusion
●● diamond model of intrustion analysis
Answer: this model defines a framework to analyze an intrusion event
(E) by exploring the relationships among four core features; adversary,
capability, infrastructure, and victim
●● open source security testing methodology manual
Answer: Developed by the Institute for Security and Open
Methodologies (ISECOM), this manual outlines every area of an
organization that needs testing and goes into details about how to
conduct the relevant tests.
●● weaponization
Answer: The second phase of the cyber kill chain.
●● The MITRE ATT&CK Matrix
Answer: This framework provides a database of observed tactics,
techniques, and procedures (TTPs) of various threat actor groups.
●● hash
Answer: The theoretically indecipherable fixed-length output of the
hashing process.
QUESTIONS AND ANSWERS FULL
SOLUTION
●● tcpdump
Answer: a command-line packet sniffing utility
●● Endpoint Detection and Response (EDR)
Answer: A software agent that collects system data and logs for analysis
by a monitoring system to provide early detection of threats
●● Sandboxing
Answer: Computing environment that is isolated from a host system to
guarantee that the environment runs in a controlled, secure fashion.
Communication links between the sandbox and the host are usually
completely prohibited so that malware or faulty software can be
analyzed in isolation and without risk to the host.
●● AbuseIPDB
Answer: a popular website used to check for IP addresses associated
with malicious activity
●● kill chain
, Answer: a model developed by Lockheed Martin that describes the
stages by which a threat actor progresses to a network intrusion
●● diamond model of intrustion analysis
Answer: this model defines a framework to analyze an intrusion event
(E) by exploring the relationships among four core features; adversary,
capability, infrastructure, and victim
●● open source security testing methodology manual
Answer: Developed by the Institute for Security and Open
Methodologies (ISECOM), this manual outlines every area of an
organization that needs testing and goes into details about how to
conduct the relevant tests.
●● weaponization
Answer: The second phase of the cyber kill chain.
●● The MITRE ATT&CK Matrix
Answer: This framework provides a database of observed tactics,
techniques, and procedures (TTPs) of various threat actor groups.
●● hash
Answer: The theoretically indecipherable fixed-length output of the
hashing process.