A security technician is planning a vulnerability assessment for an enterprise segment that includes legacy operational technology (OT) devices highly sensitive to unexpected network traffic. The technician decides to implement passive vulnerability scanning rather than active scanning. Which TWO of the following statements correctly describe the primary characteristics of passive vulnerability scanning? (Select TWO)
- It inspects captured network traffic packets in real time without sending active diagnostic probes to host systems.Cevap
- It significantly reduces the risk of causing service disruption or unexpected system crashes on fragile operational endpoints.Cevap
- CIt actively executes intrusive exploitation payloads to verify whether identified vulnerabilities are actionable.
- DIt deploys decoy honeypot resources to inline block and redirect malicious connection attempts.
- EIt injects targeted SQL injection payloads into web applications to evaluate backend database input handling.
Cevap
Passive vulnerability scanning inspects existing network traffic packets in real time without transmitting active probes, which significantly reduces the risk of service disruption on sensitive operational systems.
Passive vulnerability scanning operates non-intrusively by sniffing and analyzing network traffic as it traverses the wire. It identifies hosts, protocols, and vulnerabilities based on packet characteristics without generating probe traffic, thereby preserving uptime on fragile endpoints.
Adım Adım Çözüm
Anahtar Kavram
Passive Vulnerability Assessment Methods