Soru

Zorluk: ZorVulnerability Assessment and Security Testing Methods

A security team is designing a vulnerability assessment and testing strategy for an enterprise hybrid environment hosting critical financial microservices. The team must satisfy two core requirements: first, obtain granular, host-level visibility into operating system patch levels and local security misconfigurations; second, continuously analyze external runtime exposure without injecting active scan traffic that could disrupt live user transactions or impact service availability. Which of the following security assessment methods should the team implement to meet these operational goals? (Select TWO.)

  1. Perform credentialed vulnerability scans using dedicated, low-privilege audit service accounts on target servers.Cevap
  2. Utilize passive network vulnerability monitoring to inspect mirrored network traffic for exposed application banners and software versions.Cevap
  3. C
    Deploy an inline high-interaction honeypot within the primary microservices network to filter and drop malicious HTTP traffic.
  4. D
    Execute dynamic Cross-Site Scripting (XSS) attack scripts against internal database connection strings to verify backend query parameterization.
  5. E
    Configure perimeter firewall drop logs as the primary detective control for identifying unpatched software vulnerabilities on internal hosts.

Cevap

The team should perform credentialed vulnerability scans using audit accounts and utilize passive network vulnerability monitoring.
Credentialed vulnerability scanning allows internal inspection of host configurations, registry entries, and patch states via authenticated channels with low overhead. Passive network vulnerability monitoring observes network traffic out-of-band without generating active traffic, guaranteeing zero impact on live production transactions.

Adım Adım Çözüm

1
Evaluate requirement 1: Obtaining deep host-level visibility into patch levels and configurations with low operational disruption.
Credentialed scanning provides full visibility into internal system state without relying on aggressive network probes.
Authenticated access enables the scanner to query local package managers and configuration stores directly.
2
Evaluate requirement 2: Continuously analyzing external exposure without injecting active scan traffic into production.
Passive network vulnerability monitoring captures and inspects mirrored network traffic.
Passive monitoring operates out-of-band and introduces zero latency or active probes into live transaction flows.

Anahtar Kavram

Selecting non-disruptive active (credentialed) and passive security assessment methodologies based on operational visibility and availability requirements.
Tahmini Süre:2m 0s
Bu soruyu puanla