A security analyst is configuring an internal vulnerability assessment for a enterprise web platform located behind a reverse proxy. The platform includes legacy application services that are highly sensitive to traffic spikes. The analyst needs to obtain precise host vulnerability data while preventing service outages on legacy components. Which of the following scanner configurations and techniques should the analyst implement? (Select TWO.)
- Utilize credentialed scanning parameters to inspect local software package registries directly on host operating systems.Cevap
- Configure scan rate throttling and select non-intrusive check modules during the scan execution.Cevap
- CRely on unauthenticated banner grabbing through the reverse proxy to infer backend application patch levels.
- DExecute automated penetration testing exploitation scripts during the discovery phase to confirm vulnerability existence.
Cevap
The analyst should use credentialed scanning to examine internal package registries on hosts directly, while enabling scan rate throttling and non-intrusive checks to safeguard legacy services.
Credentialed scanning provides direct, internal access to host package managers and OS registries, yielding accurate vulnerability identification. Combining credentialed access with scan rate throttling and non-intrusive test modules ensures high detection fidelity while maintaining service stability on sensitive legacy infrastructure.
Adım Adım Çözüm
Anahtar Kavram
Vulnerability scanning configuration parameters (credentialed vs unauthenticated scanning and intrusive vs non-intrusive test controls)
Tahmini Süre:1m 30s