Soru

Zorluk: OrtaVulnerability Scanning and Assessment

A security analyst must assign the appropriate scanning methodology to four distinct security assessment requirements within an enterprise organization. Match each security assessment requirement with the most appropriate vulnerability scanning methodology.

  • Evaluating external network perimeter exposure to internet-facing probes without utilizing system privileges.External non-credentialed network scan
  • Auditing local software inventory, patch levels, and internal registry configurations with minimal network bandwidth usage.Host-based agent assessment
  • Testing network defensive security control responses by intentionally attempting known exploit payloads against dedicated sandbox targets.Intrusive vulnerability scan
  • Verifying operating system hardening configurations against established CIS benchmark standards using valid administrative domain accounts.Credentialed compliance scan

Cevap

External perimeter evaluation matches External non-credentialed network scan; Local inventory audit with low bandwidth matches Host-based agent assessment; Active payload testing matches Intrusive vulnerability scan; CIS benchmark hardening audit matches Credentialed compliance scan.
Each vulnerability scanning approach targets specific assessment goals: external unauthenticated scans measure public exposure, host agents gather local patch data with minimal network footprint, intrusive scans test active exploitability, and credentialed compliance scans verify configuration baselines against security standards.

Adım Adım Çözüm

1
Analyze the requirement for perimeter exposure without system privileges.
Identify that testing from outside without privileges requires an external non-credentialed network scan.
Non-credentialed external scans simulate an unauthenticated remote attacker evaluating the public attack surface.
2
Analyze the requirement for internal registry and patch auditing with minimal network bandwidth usage.
Identify that host-based agents collect configuration and patch data locally without sending network probes.
Agent-based scanning executes directly on the host operating system, reducing network traffic and capturing data on disconnected endpoints.
3
Analyze the requirement for testing defensive controls with exploit payloads.
Identify that active exploit attempts characterize intrusive vulnerability scanning.
Intrusive scans go beyond identification by attempting to verify exploitability, which can impact target stability.
4
Analyze the requirement for checking CIS hardening baselines using domain accounts.
Identify that credentialed compliance scans use elevated accounts to check security baseline settings.
Reading deep system configurations and registry settings requires administrative privileges.

Anahtar Kavram

Vulnerability Scanning Methodologies and Assessment Configurations
Bu soruyu puanla