Soru

Zorluk: Çok zorVulnerability Scanning and Assessment

An enterprise security architecture team is updating its vulnerability assessment strategy across a diverse hybrid infrastructure. The environment comprises internal database servers, virtualized cloud workloads, and legacy operational technology (OT) controlling industrial processes. The team must maximize vulnerability discovery accuracy while adhering to strict operational availability constraints. Which of the following scanning strategies should the security team implement to satisfy these requirements? (Select TWO.)

  1. Deploy authenticated agent-based vulnerability scanners on internal server endpoints to identify missing local patches and configuration drift without generating heavy network traffic.Cevap
  2. Utilize passive network traffic monitoring and non-intrusive asset discovery techniques across operational technology (OT) segments to evaluate vulnerabilities without interrupting control systems.Cevap
  3. C
    Implement inline web application firewalls on internal database segments as a full operational substitute for performing routine credentialed database vulnerability scans.
  4. D
    Schedule aggressive intrusive network vulnerability scans against operational technology controllers during high-volume production hours to guarantee immediate vulnerability identification.

Cevap

The security team should deploy authenticated agent-based vulnerability scanners on internal server endpoints and utilize passive network traffic monitoring on operational technology networks.
Authenticated agent-based scanning provides comprehensive insight into host-level patch management and security configurations without burdening internal networks with active network scanner traffic. Concurrently, using passive network monitoring in sensitive operational technology segments captures device and protocol vulnerability data safely without exposing critical control hardware to active probing risks.

Adım Adım Çözüm

1
Determine the optimal scanning approach for standard enterprise host systems requiring low network impact.
Authenticated agent-based scanning provides maximum local visibility into missing patches and configuration issues with negligible network traffic.
Agents leverage local system credentials and execute directly on the host OS.
2
Determine the safe scanning methodology for highly sensitive industrial control systems (OT).
Passive network traffic analysis allows vulnerability and asset discovery without injecting probes that could crash OT devices.
Availability and system stability are critical priorities in operational technology environments.
3
Evaluate and reject invalid control substitutions and high-risk operational practices.
Reject substituting vulnerability scanning with WAFs and reject running intrusive scans against OT hardware.
Preventive inline firewalls do not inspect internal vulnerability states, and intrusive active scans induce downtime.

Anahtar Kavram

Differentiating between credentialed agent-based, non-credentialed network-based, and passive vulnerability scanning methods based on asset sensitivity and operational constraints.
Bu soruyu puanla