A security administrator is designing a vulnerability scanning strategy for an enterprise environment containing both standard authenticated servers and fragile legacy embedded systems. The primary goals are to obtain deep visibility into host patches and configuration flaws on the servers while minimizing network traffic overhead and preventing disruption to sensitive legacy devices. Which of the following technical scanning approaches should the administrator implement? (Select TWO.)
- Deploy host-based vulnerability scanning agents on authenticated servers to collect local patch and configuration details with minimal network bandwidth impact.Cevap
- BConfigure high-concurrency, intrusive active network scans against legacy embedded devices to force detailed vulnerability disclosure banners.
- Schedule authenticated network vulnerability scans targeting server segments during off-peak maintenance windows.Cevap
- DDeploy inline network firewalls to automatically remediate software vulnerabilities identified during host discovery scans.
Cevap
The administrator should deploy host-based scanning agents on authenticated servers and schedule authenticated network vulnerability scans targeting server segments during off-peak maintenance windows.
Deploying host-based scanning agents provides direct, low-bandwidth access to target system patch levels and registry configurations. Additionally, conducting scheduled authenticated network scans during off-peak maintenance windows provides thorough configuration insight while preventing performance degradation on critical infrastructure.
Adım Adım Çözüm
Anahtar Kavram
Credentialed Scanning and Host-Based Scanning Agents