Soru

Zorluk: Çok zorVulnerability Scanning and Assessment

A security analyst is designing an enterprise vulnerability assessment strategy for a network that includes legacy operational technology (OT) control systems, web applications, and sensitive database servers. The analyst must achieve maximum vulnerability visibility while minimizing the risk of unexpected service disruptions or system crashes. Which of the following technical scanning approaches should the security team implement to meet these requirements? (Select TWO.)

  1. Perform credentialed vulnerability scans using read-only service accounts during established maintenance windows for server infrastructure.Cevap
  2. Utilize non-intrusive passive vulnerability scanning and network traffic monitoring for the sensitive operational technology (OT) segments.Cevap
  3. C
    Execute active exploitation modules via the vulnerability scanner to automatically verify buffer overflow vulnerabilities on production database servers.
  4. D
    Configure the vulnerability scanner to operate as an inline detective control to automatically block incoming SQL injection traffic.

Cevap

The security team should perform credentialed scans using read-only service accounts during maintenance windows and utilize non-intrusive passive vulnerability scanning for legacy operational technology segments.
Performing credentialed scans using read-only service accounts provides detailed insight into local software vulnerabilities and patch statuses while placing minimal stress on network bandwidth. For sensitive operational technology (OT) environments, passive vulnerability scanning captures and analyzes existing traffic to discover vulnerabilities without sending active probes that might crash fragile industrial controllers.

Adım Adım Çözüm

1
Analyze environmental constraints and safety requirements
Identified sensitive OT systems that cannot handle aggressive network probing and production servers requiring thorough evaluation without service disruption.
OT devices often use fragile protocol implementations that freeze when subjected to port scans or active probes.
2
Evaluate scanning methodologies for host infrastructure
Selected credentialed scanning during maintenance windows.
Credentials grant direct OS-level access to audit configuration and software inventories accurately without generating high network traffic or false positives.
3
Evaluate scanning methodologies for delicate OT infrastructure
Selected passive scanning / network traffic analysis.
Passive scanners observe network traffic passively to detect OS versions and vulnerable services without transmitting packets that could destabilize OT controllers.

Anahtar Kavram

Credentialed vs. Non-Credentialed Scanning and Passive OT Vulnerability Assessment
Bu soruyu puanla