Soru

Zorluk: KolayVulnerability Assessment and Security Testing Methods

A system administrator needs to perform a vulnerability assessment on a public web server to determine what exposed services and flaws can be discovered by an unauthenticated external attacker without administrative privileges. Which of the following assessment methods should the administrator execute?

  1. Non-credentialed vulnerability scanCevap
  2. B
    Inline honeypot deployment
  3. C
    Static application code review
  4. D
    Automated host-based firewall rule configuration

Cevap

Non-credentialed vulnerability scan
A non-credentialed vulnerability scan evaluates host endpoints and network services across network boundaries without authenticating to the operating system, accurately representing the view of an external unauthenticated attacker.

Adım Adım Çözüm

1
Identify the objective of the assessment
The goal is to evaluate exposed services and vulnerabilities from the perspective of an unauthenticated external threat actor.
Understanding the threat model determines whether privileges should be provided during testing.
2
Select the appropriate scanning methodology
A non-credentialed vulnerability scan probe endpoints across the network without system credentials.
Non-credentialed scans replicate what an outside attacker without account access can see and exploit.

Anahtar Kavram

Credentialed vs. Non-Credentialed Vulnerability Scanning
Bu soruyu puanla