Soru

Zorluk: OrtaVulnerability Scanning and Assessment

During a vulnerability assessment of an enterprise infrastructure, a scanner flags a critical unpatched remote code execution vulnerability on a core database server. The system administrator requests to mark the finding as risk-accepted without patching, citing that an inline Network Intrusion Prevention System (NIPS) is active on the network segment. Which of the following best describes the primary operational risk of relying on this compensating control instead of applying the vendor patch?

  1. Attackers who gain access to the internal network can potentially bypass the intrusion prevention system using encrypted channels or lateral movement, leaving the unpatched flaw exposed.Cevap
  2. B
    Network-level inline inspection acts as a permanent corrective control that automatically remediates the underlying application source code error.
  3. C
    Applying network filtering rules alters the software's attack surface such that future authenticated vulnerability scans will fail to execute.
  4. D
    Inline network inspection devices automatically reclassify server-side execution vulnerabilities as client-side script execution flaws.

Cevap

Attackers who gain access to the internal network can potentially bypass the intrusion prevention system using encrypted channels or lateral movement, leaving the unpatched flaw exposed.
Relying on a Network Intrusion Prevention System (NIPS) as a compensating control reduces exposure but does not remediate the vulnerability. If threat actors establish a presence within the network or encrypt their exploit payloads, the NIPS may fail to block the attack, allowing the unpatched server to be compromised.

Adım Adım Çözüm

1
Analyze the proposed risk response
The administrator proposes using an inline NIPS as a compensating control instead of remediating the software vulnerability with a vendor patch.
Compensating controls provide temporary risk reduction but do not address the root cause of a vulnerability.
2
Evaluate the limitations of network compensating controls
NIPS devices inspect traffic based on signatures and plain-text patterns; they can be bypassed via encryption, novel evasion techniques, or local attack vectors inside the network boundary.
Vulnerabilities remain active on the host as long as the underlying software code remains unpatched.
3
Determine the primary operational risk
Relying solely on NIPS leaves the host exposed if an attacker achieves internal position or uses encrypted channels to bypass network inspection.
Effective vulnerability management prioritizes patching root-cause flaws over relying exclusively on perimeter or inline filtering.

Anahtar Kavram

Vulnerability Remediation vs. Compensating Controls
Tahmini Süre:1m 30s
Bu soruyu puanla