An enterprise security analyst is configuring an automated vulnerability scanner to conduct routine compliance assessments across internal production database servers. To ensure accurate vulnerability identification while preventing system downtime or account lockouts, which of the following configuration options should the analyst implement? (Select TWO.)
- Provide read-only service account credentials to allow host-based local package and configuration inspection.Cevap
- Configure rate throttling and non-intrusive scan settings to limit concurrent query loads on target systems.Cevap
- CEnable active exploitation modules to automatically verify if identified vulnerabilities can be successfully compromised.
- DSet network firewalls to automatically trigger corrective blocking rules whenever scanner probes match SQL injection signatures.
Cevap
The analyst should provide read-only service account credentials for host-based package inspection and configure rate throttling with non-intrusive scan settings to protect target systems.
Credentialed (authenticated) scanning gives the scanner low-privilege access to target OS and software inventories, producing accurate vulnerability reports without generating high risk. Simultaneously, employing rate throttling and non-intrusive scan modules ensures that production services remain stable and operational throughout the assessment window.
Adım Adım Çözüm
Anahtar Kavram
Vulnerability Scanning Methods and Configuration Controls
Tahmini Süre:1m 30s