A security consultant is evaluating vulnerability assessment strategies for an enterprise hybrid environment that contains both standard server infrastructure and sensitive legacy Operational Technology (OT) systems. The consultant must recommend assessment techniques that accurately identify missing patches and host misconfigurations while minimizing the risk of system instability or network interruption on sensitive legacy segments. Which of the following approaches should the consultant recommend? (Select TWO.)
- Perform credentialed vulnerability scanning on host systems to directly audit installed software and missing patches with minimal network overhead.Cevap
- Deploy passive network traffic monitoring to identify legacy devices and active service vulnerabilities without transmitting probe packets to OT hosts.Cevap
- CConfigure an inline honeypot in front of legacy OT assets to serve as a primary preventive firewall control against exploit traffic.
- DDeploy Web Application Firewalls (WAF) to conduct static source code security testing on underlying host operating systems.
- EExecute intrusive penetration testing scripts containing active exploit payloads directly against sensitive OT systems during business hours.
Cevap
The consultant should recommend performing credentialed vulnerability scanning on host systems and deploying passive network traffic monitoring for legacy OT devices.
The combination of credentialed scanning and passive monitoring allows the organization to accurately assess system security posture without causing outages. Credentialed scans access host operating systems securely to audit software patch levels cleanly. Passive network traffic analysis captures packet data non-intrusively to discover legacy OT devices and services without sending disruptive probes.
Adım Adım Çözüm
Anahtar Kavram
Vulnerability Assessment and Security Testing Methods