ВУЗ: Не указан

Категория: Не указан

Дисциплина: Не указана

Добавлен: 04.12.2023

Просмотров: 193

Скачиваний: 1

ВНИМАНИЕ! Если данный файл нарушает Ваши авторские права, то обязательно сообщите нам.

ENDTERM

  1. How many penetration testing utilities does BlackArch Linux contain?

1359+

600

16

64

  1. What is one of the most common types of attack on a website, or rather on any type of SQL databases as part of sites

Exploit

SQL injection+

Debuggers

  1. Active audit, in turn, can be conditionally divided into two types: indicate the types

They are internal and external audits. Internal audits focus on the current statements about improvements, external audits focus on financial statements.

  1. Who developed the CRAMM method?

UK Security Service+

ISACA

  1. active audit is...

study of means to determine compliance with their solutions to information security problems)

study the state of the network protection system, the use of which helps a hacker to penetrate the network and cause damage to the company)

study of the state of security of an information system from the point of view of a hacker (or some attacker who is highly qualified in the field of information technology)+

  1. Significant loss of tangible assets or significant damage to the company's reputation"

Minor
ModerateMedium+high

  1. Specify the distribution kit that is used for penetration testing in various web applications
Samurai Web SecurityFramework SantokuLinuxDEFTLinuxNetworkSecurityToolkit

  1. A computer program, piece of code, or sequence of commands that uses a vulnerability to attack a system.
Exploit+SQL injectionDebuggers

  1. What are programs for finding errors in other programs, operating system kernels, SQL queries and other types of code
Debuggers+SQL injectionExploit10.ISSAF...........describes the security assessment of firewalls, routers, antivirussystemsand more+
focusedonpentestingthatorganizationsneed,processing, storing and transmitting dataaboutcardholders.focusedonpentestingthatorganizationsneed,processing, storing and transmittingdata about cardholders.

  1. What is the security distribution based on - Parrot Security OS?
DebianLinux.+UbuntuArchLinux.GentooLinux

  1. . is one of the first methods of
comprehensivetestingofinformationsecurityofanorganization..PCIDSSOSSTM+MISSAF

  1. The probability of making an attack is approximately equal to 0.5)
Very lowНизкаяMedium+

  1. What type of projects does SysTrust belong to?
TrustServiceServicesSecurityServices15. Atthelaststage oftheaudit ofinformationsecurity,recommendationsaredeveloped toimprovetheorganizationalandtechnical support of protection at the enterprise. Such recommendations include various types ofactionsaimedat. minimization of identified risks+Risk ReductionRiskavoidanceChangingthenatureoftherisk

  1. The probability of an attack is quite low. Corresponds to the numerical probability interval [0.25, 0.5)
Very lowLow+Medium

  1. In which audit do experts model the actions of an “external” intruder?
external active audit+internalactiveaudit

  1. How is the risk value determined?
Risk = (resourcecost* probability of threat): magnitudeof vulnerability+Risk = (resourcecost+ probability of threat): magnitudeof vulnerabilityRisk = (resource

cost-probability of threat): magnitudeof vulnerability

  1. Choose an attack probability that matches the description "An attack will almost never be carried out.
Corresponds to the numerical interval of the probability [0, 0.25)"Very low+Low(Medium)

  1. When conducting what type of audit with the help of special software tools, the actions of an “internal” attacker are modeled)?
(external active audit)(internalactiveaudit)+

  1. Choose the level of damage suitable for the description "Minor losses of material assets that are quickly restored, or minor consequences for the reputation of the company")
(Minor) +(Moderate)(Medium)(high)

  1. Kali Linux formerly known as.
BackTrack+WiresharkArmitageAircrack

  1. (Noticeable loss of tangible assets or moderate impact on the company's reputation")
Minor)(Moderate) +(Medium)(high)

  1. (Large loss of tangible assets and great damage to the company's reputation")
Малый(Minor)Умеренный(Moderate)Средней тяжести (Medium)Большой(high)+

  1. (How is the risk value calculated?)
Риск(a) =P(a)×Ущерб(a).+Риск (a) = Pиск(a) × Ущерб (a).Риск(a)=P(a) +Ущерб (a).Риск(a)=P(a)/Ущерб(a).

  1. (The attack will almost certainly be carried out. Corresponds to the numerical probability interval (0.75, 1])
Оченьнизкая (Very low)Низкая(low)Средняя (Medium)Высокая(High)Очень
высокая(Veryhigh)+

  1. The attack is likely to be carried out. Corresponds to the numerical probability interval (0.5, 0.75]
Оченьнизкая (Very low)Низкая(low)Средняя (Medium)+Высокая(High)

  1. (How many penetration testing utilities does Kali Linux contain?)
более чем из 600 security-утилит+13591664

  1. Specify a standard that allows financial auditors to expand the scope of their activities by using a simple and understandable set of requirements for assessing the reliability and security of IS.)
SysTrust+BSI\ITBaselineProtectionManualISO17799:CodeofPracticeforInformationSecurityManagementISO 15408: Common Criteria for Information Technology Security Evaluation30. focusedonpentesting that organizations need, processing, storing and transmitting data about cardholders.)PCIDSS+OSSTMMISSAFMIDTERM

  1. Which organization is the world leader in harmonizing and centralizing IT control practices? Какая организация является мировым лидером по гармонизации и централизации практических стандартов в области контроля за ИТ?
ISACA+IEEEISO

  1. What is the main difference between strategic IT audit and other types of IT audit? В чем состоит главное отличие стратегического ИТ -аудита от других видов ИТ- аудита?
necessarily includes an assessment of TCO by the company's information systems (обязательновключаетоценкуССВинформационнымисистемамикомпании)The ultimate goal of a strategic IT audit is to identify the reasons for the discomfort of the topmanagement of the organization in connection with the use of IT. (конечной цельюстратегического И - аудита является идентификация причин дискомфорта высшегоруководства
организации всвязи сиспользованиемИТ)+aconsultingcompanyisrequiredtoconductastrategicITaudit (для проведениястратегическогои-аудитаобязательнопривлекаетсяконсалтинговаякомпания)
  1.   1   2   3