Soru

Zorluk: ZorVulnerability Scanning and Assessment

During a routine compliance evaluation, a security analyst reviews a credentialed vulnerability scan report for an internal server subnet holding sensitive payment data. The report identifies multiple critical operating system kernel vulnerabilities on the hosts. The network operations team argues that because an inline Intrusion Prevention System (IPS) and a Web Application Firewall (WAF) inspect all incoming traffic, the host-level patch deployment can be indefinitely deferred by relying on these edge defenses. Which of the following recommendations should the security analyst provide to properly address the risk?

  1. Apply the missing operating system patches directly to the hosts during an authorized maintenance window, as network-level controls do not resolve host-based system vulnerabilities.Cevap
  2. B
    Update WAF and IPS signature rules to inspect internal traffic and suppress the vulnerability findings in subsequent scanner reports as mitigated compensating controls.
  3. C
    Reconfigure the vulnerability assessment tool to perform non-credentialed scans so that inline network security appliances can validate detective control capabilities.
  4. D
    Implement application-layer input sanitization routines at the database tier to prevent SQL injection exploits against operating system kernel functions.

Cevap

Apply the missing operating system patches directly to the hosts during an authorized maintenance window, as network-level controls do not resolve host-based system vulnerabilities.
Credentialed vulnerability scans inspect the internal system state of hosts to detect unpatched software and missing OS updates directly. Network security controls such as WAFs and IPSs act as perimeter or compensating controls, but they do not alter or fix vulnerable local code. Therefore, applying the operating system patches during a scheduled maintenance window is the only action that fully remediates the vulnerability.

Adım Adım Çözüm

1
Analyze the vulnerability scan type and findings.
The credentialed scan inspected internal system states directly and identified critical operating system kernel vulnerabilities.
Credentialed scans provide accurate, host-internal software flaw visibility regardless of perimeter network devices.
2
Evaluate the proposed mitigation alternative against security engineering principles.
IPS and WAF devices inspect network traffic but do not modify or fix flawed host software binaries.
Network controls are compensating controls that minimize exposure but do not remediate host vulnerabilities.
3
Determine the appropriate remediation path.
Remediate host operating system vulnerabilities directly via patch management during an approved maintenance window.
Host patching permanently eliminates the vulnerability, ensuring compliance and defense-in-depth.

Anahtar Kavram

Credentialed Vulnerability Scanning vs. Perimeter Compensating Controls
Tahmini Süre:2m 0s
Bu soruyu puanla