Soru

Zorluk: OrtaVulnerability Scanning and Assessment

A security analyst is designing a vulnerability assessment strategy for an enterprise environment that includes both ephemeral cloud virtual machines that dynamically auto-scale and legacy operational technology (OT) controllers that are susceptible to crashing under heavy active network traffic. Which deployment model best provides comprehensive vulnerability visibility while minimizing operational risk and disruption across both asset types?

  1. Deploy lightweight host-based scan agents on the cloud virtual machines and implement passive network vulnerability monitoring for the legacy operational technology controllers.Cevap
  2. B
    Execute high-frequency active credentialed network scans against both cloud virtual machines and legacy operational technology controllers using a centralized scanner.
  3. C
    Configure an inline intrusion prevention system (IPS) to automatically remediate vulnerabilities across cloud instances and legacy operational technology systems.
  4. D
    Conduct continuous unauthenticated external scans against management interfaces across all cloud and legacy operational technology assets.

Cevap

Deploying lightweight host-based scan agents on cloud virtual machines and implementing passive network vulnerability monitoring for legacy operational technology controllers provides full visibility while respecting operational constraints.
Host-based scan agents are ideal for short-lived, dynamically scaling cloud virtual machines because they execute locally and report state to a management console regardless of network IP changes. Passive network vulnerability monitoring collects network traffic without transmitting active probes, making it safe for delicate legacy OT systems that could malfunction when actively scanned.

Adım Adım Çözüm

1
Analyze the operational constraints of auto-scaling cloud virtual machines.
Cloud instances are ephemeral and may shut down before centralized active network scanners discover or complete scanning them. Host-based agents embedded in base images register immediately upon spin-up.
Agent-based architecture ensures visibility into short-lived workload vulnerabilities without needing network sweeps.
2
Analyze the operational constraints of legacy operational technology (OT) controllers.
Fragile industrial control devices often lack robust TCP/IP stacks and can crash when receiving unexpected port probes or high packet volumes.
Passive network scanning inspects existing network traffic without injecting probes, eliminating downtime risk for OT assets.
3
Synthesize the optimal combined vulnerability assessment approach.
Combining host agents for cloud workloads with passive scanning for OT infrastructure provides comprehensive assessment coverage tailored to each asset class.
Different operational environments require distinct scanning mechanics to balance visibility against availability.

Anahtar Kavram

Selecting appropriate vulnerability scanning methodologies (agent-based vs. passive network monitoring) based on target asset characteristics and operational risk profiles.
Bu soruyu puanla