Soru

Zorluk: OrtaVulnerability Scanning and Assessment

A security analyst is establishing a comprehensive vulnerability scanning framework for an enterprise network containing diverse operational environments. Match each vulnerability assessment requirement on the left with the scanner deployment methodology or configuration option on the right that best satisfies it.

  • Evaluating public-facing web applications behind an inline Web Application Firewall (WAF) without active security filters altering or dropping vulnerability probes.Scanner IP address whitelisting and sensor exclusion rules
  • Auditing internal system configurations and local missing patches across remote endpoints with minimal network bandwidth overhead.Credentialed agent-based scanning deployment
  • Assessing sensitive legacy Operational Technology (OT) and Supervisory Control and Data Acquisition (SCADA) networks where active probing may cause device instability.Passive network listening and traffic monitoring
  • Simulating an initial external reconnaissance phase conducted by an untrusted remote attacker targeting perimeter assets.Non-credentialed network-based perimeter scanning

Cevap

Evaluating public-facing web applications behind a WAF matches with Scanner IP address whitelisting. Auditing internal configurations across remote endpoints with minimal bandwidth matches with Credentialed agent-based scanning deployment. Assessing sensitive legacy OT/SCADA networks without causing instability matches with Passive network listening and traffic monitoring. Simulating an initial external reconnaissance phase by an untrusted attacker matches with Non-credentialed network-based perimeter scanning.
Each scanner deployment method directly addresses distinct environmental constraints: WAF IP whitelisting prevents scan interference on web applications; agent-based scanning minimizes network overhead and provides deep host visibility; passive monitoring protects legacy OT/SCADA devices from crash risks caused by active probes; and non-credentialed external scanning provides a realistic view of perimeter exposure from an attacker's perspective.

Adım Adım Çözüm

1
Analyze the web application security assessment requirement behind a WAF.
Inline WAF security controls drop or alter aggressive scanner payloads, producing incomplete scan results. Configured IP whitelisting bypasses blocking rules for legitimate scan traffic.
Security controls like WAFs must be informed of security testing to prevent false negatives caused by active payload blocking.
2
Identify the optimal scanning mechanism for remote endpoints and low-bandwidth constraints.
Agent-based scanners execute locally on the operating system, collecting inventory and patch state directly without streaming network port probes.
Agent architectures offload scanning execution to local system processes and transfer only compressed result manifests.
3
Select the appropriate technique for fragile, high-availability OT/SCADA environments.
Passive traffic monitoring analyzes network packets non-intrusively, identifying OS versions and known vulnerabilities without sending active probes.
Legacy industrial controllers frequently fault or crash when receiving unexpected or malformed TCP/IP probes generated by active vulnerability scanners.
4
Determine the methodology for simulating external threat actor perspectives.
Non-credentialed external scans inspect perimeter targets without system privileges, revealing exposed services and unpatched vulnerabilities accessible from the internet.
An unauthenticated remote attack simulation requires scanning from an external network segment without supplying valid host login credentials.

Anahtar Kavram

Vulnerability Scanner Deployment Methodologies and Operational Impact
Tahmini Süre:2m 0s
Bu soruyu puanla