1
00:00:06,450 --> 00:00:09,330
- Welcome to lesson 16, Deep Dive Quiz.

2
00:00:09,330 --> 00:00:12,330
The lesson 16 was all about
explaining various activities

3
00:00:12,330 --> 00:00:14,790
that are associated with
vulnerability management.

4
00:00:14,790 --> 00:00:18,930
We had two lessons, 16.1,
vulnerability identification,

5
00:00:18,930 --> 00:00:23,930
and 16.2, which was vulnerability
response and remediation.

6
00:00:24,330 --> 00:00:26,700
So let's do a five-question quiz together.

7
00:00:26,700 --> 00:00:27,780
Are you ready?

8
00:00:27,780 --> 00:00:30,840
Make sure you have pen
or pencil and paper,

9
00:00:30,840 --> 00:00:33,000
can put me on pause as
often as you need to

10
00:00:33,000 --> 00:00:35,400
so you answer the questions.

11
00:00:35,400 --> 00:00:37,590
All right, let's start our quiz.

12
00:00:37,590 --> 00:00:40,120
Which site would you
access to get information

13
00:00:40,120 --> 00:00:44,820
about the common vulnerability
scoring system or the CVSS?

14
00:00:44,820 --> 00:00:48,630
Nvd.nist.gov, owasp.org,

15
00:00:48,630 --> 00:00:53,133
cve.org, or aicpa.org.

16
00:00:54,090 --> 00:00:55,050
Where are you gonna go?

17
00:00:55,050 --> 00:00:56,520
We wanna get information

18
00:00:56,520 --> 00:01:00,330
about the common vulnerability
scoring system, the CVSS.

19
00:01:00,330 --> 00:01:01,800
Put me on pause for a
moment if you need to

20
00:01:01,800 --> 00:01:02,950
while I think about it.

21
00:01:05,250 --> 00:01:08,430
Well, the CVSS is maintained by NIST

22
00:01:08,430 --> 00:01:10,440
and it's part of the NVD,

23
00:01:10,440 --> 00:01:12,800
the National Vulnerability Database.

24
00:01:12,800 --> 00:01:17,160
So we're gonna go to nvd.nist.gov.

25
00:01:17,160 --> 00:01:19,620
OWASP great place to visit, right?

26
00:01:19,620 --> 00:01:24,620
OWASP is a nonprofit
organization that developers

27
00:01:25,050 --> 00:01:26,910
and coders and webmasters

28
00:01:26,910 --> 00:01:29,280
and technical folks all contribute

29
00:01:29,280 --> 00:01:32,190
to, really with the goal
of making web applications

30
00:01:32,190 --> 00:01:35,040
and mobile applications more survivable,

31
00:01:35,040 --> 00:01:37,710
more robust, more secure.

32
00:01:37,710 --> 00:01:40,528
cve.org, that's where we're
gonna go and find those CVEs.

33
00:01:40,528 --> 00:01:42,210
Another great place to go.

34
00:01:42,210 --> 00:01:43,830
And the AICPA

35
00:01:43,830 --> 00:01:46,710
is the American Institute of
Certified Public Accountants.

36
00:01:46,710 --> 00:01:49,620
Probably not relevant
to our question here.

37
00:01:49,620 --> 00:01:51,630
So nvd.nist.gov.

38
00:01:51,630 --> 00:01:52,620
Like it.

39
00:01:52,620 --> 00:01:55,083
All right, let's try
it, and that's correct.

40
00:01:56,220 --> 00:01:58,380
Time from when an exploit becomes active

41
00:01:58,380 --> 00:02:02,640
to when the number of vulnerable
systems is insignificant.

42
00:02:02,640 --> 00:02:07,500
It's this end-of-life, EOL,
a zero-day, time-to-fix,

43
00:02:07,500 --> 00:02:09,990
or the window of vulnerabilities.

44
00:02:09,990 --> 00:02:11,610
So this is a time from when the exploit

45
00:02:11,610 --> 00:02:12,900
is out there and being active

46
00:02:12,900 --> 00:02:15,780
to when there's just very
few systems to exploit

47
00:02:15,780 --> 00:02:17,280
because they've been patched.

48
00:02:17,280 --> 00:02:19,620
What is that timeframe called?

49
00:02:19,620 --> 00:02:22,260
End-of-life, zero-day,

50
00:02:22,260 --> 00:02:25,650
time-to-fix or window of vulnerability.

51
00:02:25,650 --> 00:02:27,050
Put me on pause if you want.

52
00:02:28,406 --> 00:02:32,610
Well, I'm gonna choose window
of vulnerability, right?

53
00:02:32,610 --> 00:02:34,410
End-of-life is the end of life.

54
00:02:34,410 --> 00:02:35,400
It's when a device

55
00:02:35,400 --> 00:02:39,840
or a software or subscription
becomes obsolete, right?

56
00:02:39,840 --> 00:02:42,970
Zero-day is when we have a vulnerability

57
00:02:44,245 --> 00:02:46,140
that there's been no
time for the developer

58
00:02:46,140 --> 00:02:48,780
to issue a patch yet.

59
00:02:48,780 --> 00:02:52,590
Time-to-fix, T2F is a made-up term really.

60
00:02:52,590 --> 00:02:54,930
Window of vulnerability is
what we're looking for here.

61
00:02:54,930 --> 00:02:55,763
You agree?

62
00:02:55,763 --> 00:02:58,623
Let's check, and that is correct.

63
00:03:00,990 --> 00:03:04,020
All right, we're gonna
match decision states here.

64
00:03:04,020 --> 00:03:05,850
On the right-hand side,
we have true negative,

65
00:03:05,850 --> 00:03:09,690
true positive, false
positive, and false negatives.

66
00:03:09,690 --> 00:03:10,680
On the left-hand side,

67
00:03:10,680 --> 00:03:13,740
we have normal activity
is incorrectly identified,

68
00:03:13,740 --> 00:03:16,680
abnormal activity is
incorrectly identified,

69
00:03:16,680 --> 00:03:19,140
normal activity is correctly identified,

70
00:03:19,140 --> 00:03:23,100
and abnormal activity
is correctly identified.

71
00:03:23,100 --> 00:03:25,110
So let's start with normal activity.

72
00:03:25,110 --> 00:03:28,353
So everything's okay, is
incorrectly identified.

73
00:03:30,150 --> 00:03:33,180
You wanna put me on pause,
go ahead and do that.

74
00:03:33,180 --> 00:03:35,010
All right, let's try this.

75
00:03:35,010 --> 00:03:37,770
Normal activity is incorrectly identified

76
00:03:37,770 --> 00:03:39,480
as being abnormal or problematic,

77
00:03:39,480 --> 00:03:41,133
that would be a false positive.

78
00:03:42,300 --> 00:03:45,150
Abnormal activity is
incorrectly identified.

79
00:03:45,150 --> 00:03:47,490
Again, the keyword here
is incorrectly, right?

80
00:03:47,490 --> 00:03:49,530
Incorrectly identified.

81
00:03:49,530 --> 00:03:52,083
That's gonna be a false negative.

82
00:03:53,520 --> 00:03:55,980
Normal activity is correctly identified.

83
00:03:55,980 --> 00:03:57,630
That's cool, that's a true positive.

84
00:03:57,630 --> 00:04:01,530
An abnormal activity is
correctly identified,

85
00:04:01,530 --> 00:04:03,870
that's a true negative, right?

86
00:04:03,870 --> 00:04:05,700
So we have normal activity

87
00:04:05,700 --> 00:04:08,130
is incorrectly identified, false positive.

88
00:04:08,130 --> 00:04:10,980
Abnormal activity is
incorrectly identified,

89
00:04:10,980 --> 00:04:12,270
a false negative.

90
00:04:12,270 --> 00:04:14,580
Normal activity is correctly identified,

91
00:04:14,580 --> 00:04:15,870
a true positive.

92
00:04:15,870 --> 00:04:18,330
And normal activities
correctly identified,

93
00:04:18,330 --> 00:04:19,920
a true negative.

94
00:04:19,920 --> 00:04:20,753
Agree?

95
00:04:20,753 --> 00:04:21,813
Let's check it out.

96
00:04:22,890 --> 00:04:24,300
And that is correct.

97
00:04:24,300 --> 00:04:26,100
Okay, our fourth question.

98
00:04:26,100 --> 00:04:28,590
While conducting an
authorized penetration test,

99
00:04:28,590 --> 00:04:31,650
a colleague identifies a
significant vulnerability

100
00:04:31,650 --> 00:04:34,530
in a very popular social media app.

101
00:04:34,530 --> 00:04:37,740
What would you recommend they
do with this information?

102
00:04:37,740 --> 00:04:38,573
Nothing.

103
00:04:38,573 --> 00:04:40,260
Why cause trouble, right?

104
00:04:40,260 --> 00:04:42,780
Notify CERT CC.

105
00:04:42,780 --> 00:04:44,790
Report it to the app publisher

106
00:04:44,790 --> 00:04:48,300
and also check to see if they
have a VRP or a bug bounty.

107
00:04:48,300 --> 00:04:50,280
Maybe there's a reward.

108
00:04:50,280 --> 00:04:53,880
Or make an immediate
full public disclosure.

109
00:04:53,880 --> 00:04:55,330
What are you gonna recommend?

110
00:04:57,510 --> 00:05:00,030
Well, I'm gonna recommend
that the first thing

111
00:05:00,030 --> 00:05:02,460
they do is they report
it to the app publisher.

112
00:05:02,460 --> 00:05:04,170
And why not check to see

113
00:05:04,170 --> 00:05:07,920
if there's a vulnerability
reward program or a bug bounty?

114
00:05:07,920 --> 00:05:10,140
Why not get the reward if it's there?

115
00:05:10,140 --> 00:05:12,060
But the first thing you
wanna do is you wanna go

116
00:05:12,060 --> 00:05:15,120
to the publisher or to the manufacturer

117
00:05:15,120 --> 00:05:17,220
if it happened to be in a device.

118
00:05:17,220 --> 00:05:19,410
Doing nothing, well then everybody else

119
00:05:19,410 --> 00:05:21,930
is still at risk and you have knowledge,

120
00:05:21,930 --> 00:05:24,450
it could really help them.

121
00:05:24,450 --> 00:05:26,307
Notify CERT CC, when would you do that?

122
00:05:26,307 --> 00:05:28,110
Well, let's say you report it

123
00:05:28,110 --> 00:05:30,450
to the app publisher
once, twice, three times.

124
00:05:30,450 --> 00:05:31,515
Make the emails get lost,
you try to call them as well.

125
00:05:31,515 --> 00:05:34,410
You don't hear from them.

126
00:05:34,410 --> 00:05:36,633
That's the time to notify CERT CC.

127
00:05:37,650 --> 00:05:40,110
Make an immediate full public disclosure.

128
00:05:40,110 --> 00:05:43,590
Again, you really wanna give
the publisher the ability

129
00:05:43,590 --> 00:05:46,710
to you know, understand the
vulnerability and issue a patch

130
00:05:46,710 --> 00:05:49,500
because when you make an
immediate full public disclosure,

131
00:05:49,500 --> 00:05:51,180
you're also making a disclosure

132
00:05:51,180 --> 00:05:52,447
to our adversaries, and you're saying,

133
00:05:52,447 --> 00:05:54,600
"Okay here's something
that you could exploit.

134
00:05:54,600 --> 00:05:55,620
Go at it."

135
00:05:55,620 --> 00:05:57,270
So you don't wanna do that either.

136
00:05:57,270 --> 00:05:59,643
So I'm gonna say, report
it to the app publisher

137
00:05:59,643 --> 00:06:02,343
and check to see if they have a VRP.

138
00:06:03,540 --> 00:06:04,683
And that's correct.

139
00:06:06,600 --> 00:06:08,310
All right, we are going to match

140
00:06:08,310 --> 00:06:11,250
the patch update classification here.

141
00:06:11,250 --> 00:06:13,860
On the left-hand side,
we have security updates

142
00:06:13,860 --> 00:06:18,120
update rollup, driver
update, and feature packs.

143
00:06:18,120 --> 00:06:19,110
On the right-hand side,

144
00:06:19,110 --> 00:06:21,840
we have a cumulative set
of updates and fixes,

145
00:06:21,840 --> 00:06:24,390
update files that regulate a device,

146
00:06:24,390 --> 00:06:26,430
provide new functionality

147
00:06:26,430 --> 00:06:28,860
or fixes security related vulnerabilities.

148
00:06:28,860 --> 00:06:30,815
So I wanna be able to match

149
00:06:30,815 --> 00:06:34,020
these four different
classifications of patches.

150
00:06:34,020 --> 00:06:35,550
Definitely put me on pause for a moment

151
00:06:35,550 --> 00:06:37,053
if you wanna match those up.

152
00:06:37,990 --> 00:06:39,570
Okay, a security update.

153
00:06:39,570 --> 00:06:41,580
Well, as we go through here,

154
00:06:41,580 --> 00:06:43,980
hmm, a security update
is really what fixes

155
00:06:43,980 --> 00:06:45,660
security-related vulnerabilities.

156
00:06:45,660 --> 00:06:48,420
And remember, there's
classifications within that.

157
00:06:48,420 --> 00:06:50,250
You might see critical, high severity,

158
00:06:50,250 --> 00:06:52,143
medium severity, low severity.

159
00:06:54,060 --> 00:06:56,520
Update files that regulate a device.

160
00:06:56,520 --> 00:06:58,133
Well, what are the files
that regulate a device?

161
00:06:58,133 --> 00:06:59,850
Well, that's a driver.

162
00:06:59,850 --> 00:07:01,923
So that's gonna be a driver update.

163
00:07:03,060 --> 00:07:04,890
Provides new functionality.

164
00:07:04,890 --> 00:07:07,530
Oh, that must be some new features.

165
00:07:07,530 --> 00:07:09,930
So let's look at feature pack.

166
00:07:09,930 --> 00:07:12,510
And lastly, an update rollup.

167
00:07:12,510 --> 00:07:15,030
So putting a bunch of updates together,

168
00:07:15,030 --> 00:07:19,140
that's gonna be a cumulative
set of updates and fixes.

169
00:07:19,140 --> 00:07:22,770
So security update fixes,
security related vulnerabilities.

170
00:07:22,770 --> 00:07:26,400
And update rollup is a cumulative
set of updates and fixes.

171
00:07:26,400 --> 00:07:29,970
Our driver update, updates of
files that regulate a device.

172
00:07:29,970 --> 00:07:33,090
And feature packs provide
new functionality.

173
00:07:33,090 --> 00:07:33,923
Is that what you had?

174
00:07:33,923 --> 00:07:34,756
Do you agree?

175
00:07:34,756 --> 00:07:35,589
Let's check.

176
00:07:37,050 --> 00:07:39,090
And that is correct.

177
00:07:39,090 --> 00:07:41,250
Awesome, another great job.

178
00:07:41,250 --> 00:07:42,210
Up next, we're gonna go

179
00:07:42,210 --> 00:07:45,840
into lesson 17 to
explain security alerting

180
00:07:45,840 --> 00:07:47,970
and monitoring concepts and tools.

181
00:07:47,970 --> 00:07:49,710
Another one of my favorite topics.

182
00:07:49,710 --> 00:07:50,660
I'll see you there.
