Soru

Zorluk: OrtaVulnerability Scanning and Assessment

A security administrator is designing a vulnerability scanning strategy for an enterprise environment containing both standard authenticated servers and fragile legacy embedded systems. The primary goals are to obtain deep visibility into host patches and configuration flaws on the servers while minimizing network traffic overhead and preventing disruption to sensitive legacy devices. Which of the following technical scanning approaches should the administrator implement? (Select TWO.)

  1. Deploy host-based vulnerability scanning agents on authenticated servers to collect local patch and configuration details with minimal network bandwidth impact.Cevap
  2. B
    Configure high-concurrency, intrusive active network scans against legacy embedded devices to force detailed vulnerability disclosure banners.
  3. Schedule authenticated network vulnerability scans targeting server segments during off-peak maintenance windows.Cevap
  4. D
    Deploy inline network firewalls to automatically remediate software vulnerabilities identified during host discovery scans.

Cevap

The administrator should deploy host-based scanning agents on authenticated servers and schedule authenticated network vulnerability scans targeting server segments during off-peak maintenance windows.
Deploying host-based scanning agents provides direct, low-bandwidth access to target system patch levels and registry configurations. Additionally, conducting scheduled authenticated network scans during off-peak maintenance windows provides thorough configuration insight while preventing performance degradation on critical infrastructure.

Adım Adım Çözüm

1
Analyze requirement for server visibility and network bandwidth constraint.
Host-based agents allow deep inspection of patches and OS configurations locally while generating negligible network traffic.
Agents execute scans locally rather than sending heavy probe packets across network segments.
2
Determine safe scanning methodology for enterprise server networks without affecting operational productivity.
Scheduling authenticated network scans during off-peak windows provides verified administrative-level vulnerability results without risking network congestion during business hours.
Authenticated scans log directly into target hosts to verify missing patches, eliminating false positives common in unauthenticated banner checks.
3
Evaluate risk regarding legacy embedded endpoints.
Avoid intrusive scans on legacy devices, as their limited network stacks can crash under high packet volumes or aggressive probing.
Passive monitoring or restricted non-intrusive scans are preferred for fragile legacy assets.

Anahtar Kavram

Credentialed Scanning and Host-Based Scanning Agents
Bu soruyu puanla