Soru

Zorluk: OrtaVulnerability Assessment and Security Testing Methods

An enterprise security team must perform routine vulnerability assessments across 5,000 corporate workstations distributed over low-bandwidth branch network links. The assessment must accurately detect missing operating system patches and local registry misconfigurations while minimizing network traffic and preventing false positives caused by endpoint firewalls. Which of the following vulnerability assessment methods should the security team implement?

  1. Deploying agent-based credentialed assessment software to execute scans locally on each endpointCevap
  2. B
    Running unauthenticated active network vulnerability scans across the remote branch subnets
  3. C
    Positioning inline honeypots within each branch network segment to record endpoint security posture
  4. D
    Executing dynamic application security testing scripts focused on database injection flaws across endpoint management ports

Cevap

Deploying agent-based credentialed assessment software to execute scans locally on each endpoint
Agent-based vulnerability scanning utilizes locally installed software agents that execute vulnerability checks directly on the host operating system using local privileges. This approach eliminates WAN bandwidth consumption because raw scan packets do not travel over the network, bypasses host firewall restrictions, and provides highly accurate patch and configuration state visibility.

Adım Adım Çözüm

1
Analyze the operational constraints of the scenario
Identified low WAN bandwidth, potential firewall interference, and the need for detailed local patch/registry inspection across distributed endpoints.
Target environment constraints dictate which assessment architecture is feasible.
2
Compare vulnerability testing methodologies against the requirements
Agent-based assessment performs local processing and transmits only summary results, bypassing network bandwidth bottlenecks and host firewalls.
Host agents leverage local administrative privileges to inspect the software inventory directly.

Anahtar Kavram

Agent-Based vs. Network-Based Vulnerability Assessment
Bu soruyu puanla