1
00:00:06,540 --> 00:00:09,540
- Welcome to Lesson 27, Deep Dive Quiz.

2
00:00:09,540 --> 00:00:10,710
Now, in Lesson 27,

3
00:00:10,710 --> 00:00:14,430
we focused on explaining types
of audits and assessments.

4
00:00:14,430 --> 00:00:17,580
In 27.1, we looked at
audits and assurance,

5
00:00:17,580 --> 00:00:20,490
including SSAE 18 reports.

6
00:00:20,490 --> 00:00:23,820
In 27.2, we looked at
penetration testing concepts,

7
00:00:23,820 --> 00:00:25,440
and then in 27.3,

8
00:00:25,440 --> 00:00:29,370
we looked at penetration
testing tools and techniques.

9
00:00:29,370 --> 00:00:31,440
So, you ready to do a quiz? All right.

10
00:00:31,440 --> 00:00:33,600
Make sure you've got that pen or pencil

11
00:00:33,600 --> 00:00:34,980
and that paper ready.

12
00:00:34,980 --> 00:00:36,240
This is really our 27th one,

13
00:00:36,240 --> 00:00:38,400
so I probably don't need
to tell you that anymore,

14
00:00:38,400 --> 00:00:41,100
but I do wanna make sure
that you stop me, right?

15
00:00:41,100 --> 00:00:42,750
Pause me as much as you need

16
00:00:42,750 --> 00:00:44,700
so that you can get the answers.

17
00:00:44,700 --> 00:00:46,350
All right, let's start that quiz.

18
00:00:49,680 --> 00:00:50,513
Question One.

19
00:00:50,513 --> 00:00:55,110
We are gonna match the
SSAE-related term and description.

20
00:00:55,110 --> 00:00:58,350
Let me scroll down a little
bit so you can see all of it.

21
00:00:58,350 --> 00:01:00,000
We've got, on the left-hand side,

22
00:01:00,000 --> 00:01:04,200
Type 2, Type 1, SOC1, SOC2, SOC3.

23
00:01:04,200 --> 00:01:05,430
On the right-hand side, we have,

24
00:01:05,430 --> 00:01:08,880
based on the trust service
principles, or the TSPs,

25
00:01:08,880 --> 00:01:11,850
relevant to user entities
financial statements,

26
00:01:11,850 --> 00:01:14,010
designed for public distribution,

27
00:01:14,010 --> 00:01:16,800
measures effectiveness
for a specific period,

28
00:01:16,800 --> 00:01:19,020
or a point-in-time-report.

29
00:01:19,020 --> 00:01:19,853
Right.

30
00:01:19,853 --> 00:01:23,670
These are all SSAE 18-related
terms and descriptions.

31
00:01:23,670 --> 00:01:26,220
So go ahead and put me on
pause and match these up.

32
00:01:27,090 --> 00:01:27,923
All right, let's try it.

33
00:01:27,923 --> 00:01:32,820
So our first one, based on trust
service principles or TSPs,

34
00:01:32,820 --> 00:01:34,503
that's gonna be our SOC2.

35
00:01:35,760 --> 00:01:39,360
Measures effectiveness for
a specific period of time,

36
00:01:39,360 --> 00:01:42,063
now that's gonna be a
type, that is a type 2.

37
00:01:42,901 --> 00:01:46,860
Relevant to the user entity's
financial statements,

38
00:01:46,860 --> 00:01:49,020
that's what we used to call a SAS 70,

39
00:01:49,020 --> 00:01:50,883
and that's gonna be a SOC1.

40
00:01:52,440 --> 00:01:56,100
Designed for public
distribution, that's a SOC3.

41
00:01:56,100 --> 00:01:58,140
And it does the same type
of testing as a SOC2,

42
00:01:58,140 --> 00:02:00,390
but doesn't have any
proprietary information

43
00:02:00,390 --> 00:02:02,430
and doesn't detail any of the testing.

44
00:02:02,430 --> 00:02:05,400
And a type 1 is a point in time.

45
00:02:05,400 --> 00:02:06,660
So let's go through that.

46
00:02:06,660 --> 00:02:11,160
A type two SSAE 18 is a
measures effectiveness

47
00:02:11,160 --> 00:02:12,390
for a specific period.

48
00:02:12,390 --> 00:02:13,980
A type one is a point in time.

49
00:02:13,980 --> 00:02:17,040
As of a particular date,
do those controls exist?

50
00:02:17,040 --> 00:02:18,870
A SOC1 is relevant

51
00:02:18,870 --> 00:02:21,480
to the user entity's financial statements,

52
00:02:21,480 --> 00:02:24,150
and a SOC1 is an agreed upon scope

53
00:02:24,150 --> 00:02:27,360
between the audit firm and
the company being audited.

54
00:02:27,360 --> 00:02:30,990
A SOC2 is based on the
trust service principles

55
00:02:30,990 --> 00:02:33,240
where the organization
that's being audited

56
00:02:33,240 --> 00:02:36,030
gets to choose what categories
they wanna be audited on,

57
00:02:36,030 --> 00:02:38,580
but they don't have any
say over the controls

58
00:02:38,580 --> 00:02:40,050
or the control criteria.

59
00:02:40,050 --> 00:02:43,350
That's all done by the auditing firm.

60
00:02:43,350 --> 00:02:44,730
Remember, the SOC2 is also gonna have

61
00:02:44,730 --> 00:02:47,340
a lot of proprietary information in it,

62
00:02:47,340 --> 00:02:50,370
and it will detail all of
the testing and the results.

63
00:02:50,370 --> 00:02:53,670
So you'll probably have to
sign an NDA to get a SOC2.

64
00:02:53,670 --> 00:02:55,589
And then we get to a SOC3.

65
00:02:55,589 --> 00:02:58,890
And SOC3, the same type of
testing has been done as a SOC2,

66
00:02:58,890 --> 00:03:00,780
but all of that proprietary information

67
00:03:00,780 --> 00:03:03,600
and that testing information
has been stripped out.

68
00:03:03,600 --> 00:03:06,060
It's really designed
for public distribution,

69
00:03:06,060 --> 00:03:07,981
kinda more of a marketing tool.

70
00:03:07,981 --> 00:03:09,750
You agree?

71
00:03:09,750 --> 00:03:11,700
All right, let's try it.

72
00:03:11,700 --> 00:03:12,933
And that is correct.

73
00:03:14,070 --> 00:03:14,903
All right.

74
00:03:14,903 --> 00:03:16,350
Your organization is
negotiating a contract

75
00:03:16,350 --> 00:03:17,490
with a third-party

76
00:03:17,490 --> 00:03:19,890
to conduct quarterly penetration tests.

77
00:03:19,890 --> 00:03:21,810
It is operationally critical

78
00:03:21,810 --> 00:03:25,530
that compromise exploitation
not be permitted.

79
00:03:25,530 --> 00:03:27,930
How would you best
communicate this requirement?

80
00:03:28,770 --> 00:03:31,440
Disallow all escalation
of privilege attempts.

81
00:03:31,440 --> 00:03:33,780
In the ROE, state that all testing

82
00:03:33,780 --> 00:03:36,006
follow proof-of-concept protocol.

83
00:03:36,006 --> 00:03:38,850
Inform target personnel
of the testing schedule

84
00:03:38,850 --> 00:03:41,490
and have them plan for potential exploits.

85
00:03:41,490 --> 00:03:45,633
Or, document expectations and
requirements in an audit plan.

86
00:03:47,880 --> 00:03:49,410
And so what do we have here?

87
00:03:49,410 --> 00:03:52,290
Right, your organization
is negotiating a contract.

88
00:03:52,290 --> 00:03:54,870
You're gonna have these
quarterly penetration tests,

89
00:03:54,870 --> 00:03:58,888
but you absolutely do not
want compromise exploitation,

90
00:03:58,888 --> 00:03:59,721
right?

91
00:03:59,721 --> 00:04:00,554
What do you want instead?

92
00:04:00,554 --> 00:04:01,980
Think about that.

93
00:04:01,980 --> 00:04:05,850
And how are we going to best
communicate that requirement?

94
00:04:05,850 --> 00:04:06,810
Go ahead and put me on pause

95
00:04:06,810 --> 00:04:08,903
while you read through
those again, if you want.

96
00:04:10,470 --> 00:04:12,420
Well, I'm gonna choose, in my ROE,

97
00:04:12,420 --> 00:04:14,160
that's my rules of engagement,

98
00:04:14,160 --> 00:04:16,380
I'm gonna state that all testing

99
00:04:16,380 --> 00:04:18,810
follow proof-of-concept protocol,

100
00:04:18,810 --> 00:04:21,390
which is the opposite of
compromise exploitation.

101
00:04:21,390 --> 00:04:25,290
Compromise exploitation is
just go for it, do it all,

102
00:04:25,290 --> 00:04:27,480
where proof-of-concept
says just do enough,

103
00:04:27,480 --> 00:04:29,640
so that you can prove to me or show me

104
00:04:29,640 --> 00:04:32,482
that this exploit is possible.

105
00:04:32,482 --> 00:04:35,220
Disallowing all escalation
of privilege attempts.

106
00:04:35,220 --> 00:04:36,750
That means finding
everything that would have

107
00:04:36,750 --> 00:04:39,300
a related vulnerability,
which isn't a bad idea,

108
00:04:39,300 --> 00:04:42,333
except that it's not relevant
to our question here.

109
00:04:43,530 --> 00:04:45,840
Inform our target personnel of the testing

110
00:04:45,840 --> 00:04:47,700
and have them plan for potential exploits.

111
00:04:47,700 --> 00:04:49,410
Well, we don't want those exploits.

112
00:04:49,410 --> 00:04:51,600
That's what we wanna stop upfront.

113
00:04:51,600 --> 00:04:55,200
And document expectations and
requirements in an audit plan

114
00:04:55,200 --> 00:04:57,570
where we use an audit plan for an audit,

115
00:04:57,570 --> 00:05:01,860
but for a penetration test or
for a vulnerability assessment

116
00:05:01,860 --> 00:05:03,570
or a configuration assessment,

117
00:05:03,570 --> 00:05:06,360
we use an ROE, or rules of engagement.

118
00:05:06,360 --> 00:05:07,710
So I'm gonna choose an ROE,

119
00:05:07,710 --> 00:05:11,163
state that all testing follow
proof-of-concept protocol.

120
00:05:12,600 --> 00:05:14,790
Let's try it. Let's see what you think.

121
00:05:14,790 --> 00:05:16,290
And that's correct.

122
00:05:16,290 --> 00:05:18,390
All right. Number three.

123
00:05:18,390 --> 00:05:20,640
This technique is used
to infer characteristics

124
00:05:20,640 --> 00:05:22,020
about a population,

125
00:05:22,020 --> 00:05:25,045
based upon the characteristics
of a chosen group.

126
00:05:25,045 --> 00:05:30,045
It says, examining, sampling,
auditing, or interviewing.

127
00:05:30,180 --> 00:05:32,943
So we're inferring characteristics
about a population,

128
00:05:32,943 --> 00:05:36,120
based on the characteristics
of a chosen group

129
00:05:36,120 --> 00:05:37,988
of a smaller group.

130
00:05:37,988 --> 00:05:39,420
What is it?

131
00:05:39,420 --> 00:05:40,680
Evidence? Excuse me.

132
00:05:40,680 --> 00:05:44,910
Examining, sampling,
auditing, or interviewing.

133
00:05:44,910 --> 00:05:45,960
Are you ready?

134
00:05:45,960 --> 00:05:47,580
I'm gonna choose sampling,

135
00:05:47,580 --> 00:05:49,440
because sampling is a
technique that we use

136
00:05:49,440 --> 00:05:52,320
to infer characteristics
about a population,

137
00:05:52,320 --> 00:05:54,870
based upon the characteristics
of a chosen group

138
00:05:54,870 --> 00:05:56,713
of the sample group.

139
00:05:56,713 --> 00:05:58,050
You agree?

140
00:05:58,050 --> 00:06:00,090
Let's check, and that is correct.

141
00:06:00,090 --> 00:06:02,310
Okay. Question number four.

142
00:06:02,310 --> 00:06:06,150
This exploitation technique
uses a weakness on one system

143
00:06:06,150 --> 00:06:08,850
to access a better protected system.

144
00:06:08,850 --> 00:06:12,757
Is this escalation of privileges,
persistence, pivoting,

145
00:06:12,757 --> 00:06:14,373
or teaming?

146
00:06:15,390 --> 00:06:17,520
It's the exploitation
technique that uses a weakness

147
00:06:17,520 --> 00:06:18,353
on one system

148
00:06:18,353 --> 00:06:20,550
to access a better protected system.

149
00:06:20,550 --> 00:06:23,493
You can put me on pause if
you wanna think about it.

150
00:06:24,900 --> 00:06:26,400
Well, let's go through them.

151
00:06:26,400 --> 00:06:27,480
Escalation of privilege

152
00:06:27,480 --> 00:06:29,512
is when we're going to
exploit a vulnerability

153
00:06:29,512 --> 00:06:33,870
that would allow us to have
privilege access to a resource

154
00:06:33,870 --> 00:06:36,210
really over and above
what a user would have

155
00:06:36,210 --> 00:06:37,800
or an application would have.

156
00:06:37,800 --> 00:06:39,210
So that's not it.

157
00:06:39,210 --> 00:06:41,550
Persistence is the act
of installing something

158
00:06:41,550 --> 00:06:45,240
like creating users or
installing malware or backdoors

159
00:06:45,240 --> 00:06:47,820
or rootkits that survive reboots.

160
00:06:47,820 --> 00:06:50,160
Well, that's not what we're
talking about here, either.

161
00:06:50,160 --> 00:06:51,300
Ah, pivoting.

162
00:06:51,300 --> 00:06:54,900
Pivoting is the technique that
uses a weakness on one system

163
00:06:54,900 --> 00:06:57,360
to access a better protected system.

164
00:06:57,360 --> 00:06:58,890
So I'm gonna choose that.

165
00:06:58,890 --> 00:07:01,620
Teaming, that was just a
term that was thrown in here.

166
00:07:01,620 --> 00:07:03,090
So do you agree with pivoting?

167
00:07:03,090 --> 00:07:06,605
Let's check, and that's correct.

168
00:07:06,605 --> 00:07:08,190
All right.

169
00:07:08,190 --> 00:07:10,519
We are going to put the
penetration test phases

170
00:07:10,519 --> 00:07:12,213
in the correct order.

171
00:07:13,050 --> 00:07:15,870
So our options here are
additional research,

172
00:07:15,870 --> 00:07:18,720
exploitation, analysis and reporting,

173
00:07:18,720 --> 00:07:21,900
continued exploitation,
active reconnaissance,

174
00:07:21,900 --> 00:07:23,640
and passive reconnaissance.

175
00:07:23,640 --> 00:07:26,040
And we'll start with number
one as the first step.

176
00:07:26,040 --> 00:07:27,050
So go ahead and put me on pause,

177
00:07:27,050 --> 00:07:28,740
so you can get these in the right order.

178
00:07:28,740 --> 00:07:29,643
So add 'em down.

179
00:07:31,080 --> 00:07:33,150
Okay, so what are we gonna start with?

180
00:07:33,150 --> 00:07:36,063
We're gonna start with
passive footprinting.

181
00:07:37,080 --> 00:07:38,160
That's the first thing we're gonna do.

182
00:07:38,160 --> 00:07:39,990
So no interaction, right?

183
00:07:39,990 --> 00:07:41,940
Just learning about the target.

184
00:07:41,940 --> 00:07:43,800
Then we wanna dive in a little bit deeper

185
00:07:43,800 --> 00:07:47,430
and get more specific
information about the target.

186
00:07:47,430 --> 00:07:50,820
That's gonna be our active reconnaissance.

187
00:07:50,820 --> 00:07:52,140
Oops, active reconnaissance.

188
00:07:52,140 --> 00:07:53,430
There we go.

189
00:07:53,430 --> 00:07:54,263
All right.

190
00:07:54,263 --> 00:07:56,501
After we have done our
active reconnaissance

191
00:07:56,501 --> 00:07:58,500
and our passive reconnaissance,

192
00:07:58,500 --> 00:08:00,450
we should have enough information

193
00:08:00,450 --> 00:08:03,123
to begin crafting our exploits.

194
00:08:03,990 --> 00:08:05,400
So exploitation.

195
00:08:05,400 --> 00:08:07,110
Now that exploitation could be manual,

196
00:08:07,110 --> 00:08:08,400
it could be automated,

197
00:08:08,400 --> 00:08:10,620
it could be like right
out-of-the-box exploits,

198
00:08:10,620 --> 00:08:13,440
or it could be specifically
crafted exploits.

199
00:08:13,440 --> 00:08:15,120
But generally those first exploits,

200
00:08:15,120 --> 00:08:18,000
we're gonna learn more about our target.

201
00:08:18,000 --> 00:08:19,260
So that might mean

202
00:08:19,260 --> 00:08:21,720
that we're gonna do some
additional research,

203
00:08:21,720 --> 00:08:24,040
and after we've done
some additional research,

204
00:08:24,040 --> 00:08:26,340
we're gonna do our continued exploitation.

205
00:08:26,340 --> 00:08:28,230
And that's a very iterative process.

206
00:08:28,230 --> 00:08:30,060
That might happen over and over again.

207
00:08:30,060 --> 00:08:31,710
We learn something, we do some research,

208
00:08:31,710 --> 00:08:32,730
we continue exploiting.

209
00:08:32,730 --> 00:08:36,153
We keep fine-tuning, right,
what our exploitations are.

210
00:08:37,050 --> 00:08:39,933
And then lastly, we have
analysis and reporting.

211
00:08:40,920 --> 00:08:43,800
So, passive footprinting,
active reconnaissance,

212
00:08:43,800 --> 00:08:47,970
exploitation, additional
research, continued exploitation,

213
00:08:47,970 --> 00:08:50,460
and analysis and reporting.

214
00:08:50,460 --> 00:08:52,017
Now, just in one and
two, just to be clear,

215
00:08:52,017 --> 00:08:53,700
footprinting and reconnaissance,

216
00:08:53,700 --> 00:08:55,890
those are interchangeable terms.

217
00:08:55,890 --> 00:08:57,810
All right, so do you agree with our order?

218
00:08:57,810 --> 00:08:58,960
All right, let's check.

219
00:09:00,090 --> 00:09:01,890
And that is correct.

220
00:09:01,890 --> 00:09:03,720
Awesome. Another great job.

221
00:09:03,720 --> 00:09:04,553
All right.

222
00:09:04,553 --> 00:09:06,787
Up next, we're going
into Lesson 28, which is:

223
00:09:06,787 --> 00:09:11,787
Given a scenario, implement
security awareness practices.

224
00:09:11,880 --> 00:09:12,830
I'll see you there.
