Soru

Zorluk: OrtaVulnerability Scanning and Assessment

An organization must conduct scheduled external vulnerability assessments of its public-facing web applications to satisfy regulatory compliance. During previous unauthenticated scans, the perimeter web application firewall (WAF) repeatedly blocked the scanner's IP address, resulting in incomplete scan reports and false positives. Which scanning strategy should the security analyst implement to obtain comprehensive assessment results without disabling perimeter defenses for external traffic?

  1. Perform authenticated application scanning using scanner source IP addresses whitelisted specifically on the WAFCevap
  2. B
    Reconfigure the inline Intrusion Prevention System to operate in passive monitoring mode to identify web application flaws
  3. C
    Execute an aggressive, non-credentialed port scan using randomized source ports to overwhelm perimeter firewall logging
  4. D
    Analyze client-side web browser logs using static code analysis tools to detect database vulnerabilities on the backend server

Cevap

Perform authenticated application scanning using scanner source IP addresses whitelisted specifically on the WAF
Whitelisting the dedicated vulnerability scanner's IP address on the WAF allows security probes to reach target applications without triggering defensive blocks. Combining this with authenticated access enables comprehensive assessment of application code and system configurations while keeping WAF protections fully enabled for untrusted external traffic.

Adım Adım Çözüm

1
Identify the primary root cause of incomplete scanner results.
The perimeter WAF actively identifies scanner probes as attack traffic and blocks the scanner's source IP address.
Unauthenticated vulnerability probes mimic real-world attack traffic, triggering automated defensive rules.
2
Determine the appropriate configuration to allow legitimate scanner traffic.
Whitelisting the dedicated scanner's IP address on the WAF allows scan traffic through while keeping protection active for all other internet traffic.
Targeted IP exceptions permit authorized security testing without lowering baseline enterprise security.
3
Select the scan type that provides maximum accuracy and reduces false positives.
Executing an authenticated scan provides deep visibility into application states and internal patch levels.
Credentialed scans bypass superficial banner checks, reducing false positives and identifying complex vulnerabilities.

Anahtar Kavram

Credentialed Vulnerability Scanning and Defensive Control Whitelisting
Tahmini Süre:1m 30s
Bu soruyu puanla