A security engineer is refining the vulnerability assessment strategy for an enterprise data center hosting high-availability web applications and legacy backend databases. To ensure deep asset visibility while mitigating the risk of service disruption and unauthorized network impact, which of the following operational practices should the engineer implement? (Select TWO.)
- Schedule intrusive vulnerability scanning templates exclusively during pre-approved maintenance windows.Cevap
- Use credentialed access to audit local system configurations, installed software inventories, and missing patches.Cevap
- CDeploy network perimeter firewalls to automatically repair application-layer vulnerabilities identified by the scanner.
- DClassify the automated vulnerability scanner as a corrective control designed to remediate security weaknesses automatically.
Cevap
The security engineer should schedule intrusive vulnerability scan templates exclusively during pre-approved maintenance windows and use credentialed access to audit local configurations, installed software, and missing patches.
Scheduling intrusive scans during maintenance windows protects production availability from unexpected system crashes, while credentialed scanning provides precise internal configuration visibility with minimal network impact and reduced false positives.
Adım Adım Çözüm
Anahtar Kavram
Vulnerability Scanning Methodologies and Operational Controls