During a scheduled vulnerability assessment of an enterprise network segment, an automated scanner causes several legacy network switches to become unresponsive due to resource exhaustion from high-frequency port probing and service discovery requests. Which of the following adjustments should the security engineer implement to maintain visibility into these network devices without causing service disruptions?
- Reduce the scan throttle rate and switch to a non-intrusive scan profile for the affected network segment.Answer
- BDeploy host-based vulnerability scanning agents directly onto the switch firmware.
- CPlace an inline web application firewall in front of the management interfaces to filter scanner traffic.
- DConfigure SIEM correlation rules to suppress network disruption alerts generated during scanning windows.
Answer
Reduce the scan throttle rate and switch to a non-intrusive scan profile for the affected network segment.
Reducing the scan intensity (throttling) and switching to non-intrusive scan settings prevents resource exhaustion on sensitive hardware while allowing the scanner to gather essential service and version information safely.
Step-by-Step Solution
Key Concept
Vulnerability Scanner Tuning and Safe Scanning Operations
Estimated Time:1m 15s