A system administrator needs to perform a vulnerability assessment on a public web server to determine what exposed services and flaws can be discovered by an unauthenticated external attacker without administrative privileges. Which of the following assessment methods should the administrator execute?
- Non-credentialed vulnerability scanAnswer
- BInline honeypot deployment
- CStatic application code review
- DAutomated host-based firewall rule configuration
Answer
Non-credentialed vulnerability scan
A non-credentialed vulnerability scan evaluates host endpoints and network services across network boundaries without authenticating to the operating system, accurately representing the view of an external unauthenticated attacker.
Step-by-Step Solution
Key Concept
Credentialed vs. Non-Credentialed Vulnerability Scanning