Soru

Zorluk: OrtaVulnerability Scanning and Assessment

An organization has expanded its remote workforce, resulting in laptops connecting to the enterprise network via VPN at unpredictable times. The security operations team observes that scheduled centralized network vulnerability scans routinely miss these endpoints because they are disconnected or powered off during scan execution windows. Which of the following scanning solutions best enables the security team to maintain continuous vulnerability visibility for these roaming endpoints?

  1. Deploy host-based vulnerability scanning agents to locally assess system configurations and transmit results when connectivity is established.Cevap
  2. B
    Configure network firewall rules to block network access for any endpoint that has not completed a centralized network scan within 30 days.
  3. C
    Increase the frequency and concurrent thread density of active network vulnerability scans across the VPN subnet range.
  4. D
    Implement web application vulnerability scanning on corporate remote access portals to inspect incoming session payloads.

Cevap

Deploying host-based vulnerability scanning agents to locally assess system configurations and transmit results when connectivity is established.
Deploying host-based vulnerability scanning agents directly onto endpoints allows vulnerability data to be collected locally regardless of whether the machine is connected to the corporate network. When the roaming device connects to the internet or VPN, the lightweight agent securely transmits its local scan results back to the central management console, eliminating blind spots caused by rigid network scan windows.

Adım Adım Çözüm

1
Analyze the operational constraints of the remote endpoint environment.
Identified that endpoints are frequently offline or off-network during scheduled centralized network scan windows, causing missing assessment data.
Centralized network scanners require active network reachability and host uptime during the scan execution window.
2
Evaluate vulnerability assessment methodologies suited for transient/roaming hosts.
Host-based agents execute assessments locally on the endpoint OS using local resources and cache scan reports until network connectivity is restored.
Agent-based scanning decouples vulnerability assessment timing from network availability.
3
Select the optimal solution that resolves the visibility gap without impacting operational workflows.
Deploying agent-based software ensures consistent, up-to-date vulnerability tracking across roaming laptops.
Host agents provide continuous visibility regardless of endpoint location or VPN connection schedules.

Anahtar Kavram

Agent-Based vs. Network-Based Vulnerability Scanning
Tahmini Süre:1m 30s
Bu soruyu puanla