Soru

Zorluk: OrtaVulnerability Scanning and Assessment

A security operations team is configuring an internal vulnerability assessment for a critical database cluster. During initial test runs, network-based scans produced incomplete results because inline Network Intrusion Prevention System (NIPS) appliances dropped scanning probes after flagging them as port scanning attacks. Which of the following approaches should the team implement to ensure comprehensive vulnerability visibility without triggering network traffic blocking? (Select TWO.)

  1. Deploy credentialed host-based vulnerability agents directly on the target cluster nodes.Cevap
  2. Configure NIPS bypass rules for the dedicated vulnerability scanner IP address and apply scan throttling.Cevap
  3. C
    Switch the host-based firewalls on target nodes from stateful filtering to stateless mode for the duration of the scan.
  4. D
    Enable active web application vulnerability exploitation modules on the network vulnerability scanner.

Cevap

The correct approaches are to deploy credentialed host-based vulnerability agents directly on the cluster nodes and to configure NIPS bypass rules for the scanner IP address along with scan throttling.
Deploying host-based credentialed agents allows local auditing of installed patches and configurations without generating high-volume network probes that trigger inline IPS drops. Additionally, setting up IPS allowlist rules for the designated scanner IP address while enabling scan throttling ensures network probe traffic is authorized and does not disrupt network performance.

Adım Adım Çözüm

1
Identify the primary cause of scan failure.
The NIPS drops probe packets due to detecting high-volume network scanning signatures.
Inline network security appliances misidentify automated scanner traffic as malicious port scanning activity.
2
Evaluate host-based local assessment solutions.
Deploying host-based agents enables local inventory and patch audits.
Agent-based scanning inspects system state locally, eliminating heavy network probe traffic and bypassing network IPS inspection.
3
Evaluate network-based scanner adjustment techniques.
Allowlisting the scanner IP on NIPS and throttling request rates allows network probes through cleanly.
NIPS bypass rules prevent packet dropping for authorized scanner IPs, while rate throttling avoids network overload.

Anahtar Kavram

Vulnerability Scanner Configuration and Intrusion Defense Interoperability
Bu soruyu puanla