A security administrator must evaluate an operational technology (OT) network supporting critical infrastructure. The administrator needs to identify missing operating system patches and open ports without running tests that could potentially disrupt operations or crash sensitive services. Which type of vulnerability scan should the administrator perform?
- A non-intrusive scanCevap
- BAn intrusive scan
- CA web application SQL injection exploitation test
- DA detective control audit
Cevap
A non-intrusive scan should be performed because it detects potential vulnerabilities without executing active exploit payloads or sending aggressive network traffic that could interrupt sensitive services.
Non-intrusive scanning identifies potential security weaknesses by checking host responses and software versions against known vulnerability signatures without executing invasive tests that could cause system failure.
Adım Adım Çözüm
Anahtar Kavram
Non-intrusive vs. Intrusive Vulnerability Scanning