ANSWERS WITH SOLUTIONS 2024
Software Capability Maturity Model (CMM) - ANSWER I Really Don't Mind Over Eating:
I = Initial
R = Repeatable
D = Defined
M = Managed
O = Optimized
Initial Repeatable Defined Managed Optimized
Common Criteria - ANSWER ISO 15408
Peter Pan on Toast
PP = Protection profile
TOE = Target of Evaluation
ST = Security Target (Functional & Assurance)
Pen Testing - ANSWER DENVER
Discovery: Footprint gather info
ENumeration: Port scans, Resource ID
Vulnerability Mapping:
Exploiting
Reporting to Management
Pen test types - ANSWER Blind - assessors have only public data
Double Blind - Security staff is not notified.
Test for DB transactions - ANSWER ACID
Atomicity
, Consistent
Isolation
Durability
Access Control - ANSWER Types of ___________________
PDC-DRCD
Pretty Detectives Correcting Detours Recovers Compensated Directors
Preventative
Detective
Corrective
Deterrant
Recovery
Compensating
Directive
Access Control - ANSWER _____________ has 3 broad categories.
Administrative (aka Management)
Technical / Logical
Physical
Phreak Attacks - Order of creation - ANSWER BRB: Be Right Back
Blue Box: Make free calls
Red box: falling coin sound; 5 cents per tone.
Black box: Receive free calls
Data transmission construction TCP - ANSWER Did Someone Pay for Bits?