Soru

Zorluk: ZorVulnerability Assessment and Security Testing Methods

An enterprise security analyst is designing a vulnerability assessment program for critical hybrid-cloud server infrastructure. The organization mandates that the assessment methods must identify missing host-level OS security patches and detect cleartext sensitive data transfers without sending disruptive synthetic network probes across production subnets. Which TWO of the following vulnerability assessment and testing techniques should the analyst implement? (Select TWO.)

  1. Deploying agent-based credentialed scanning tools directly on server instances to audit OS configurations and installed software.Cevap
  2. Implementing passive network traffic monitoring to observe data transmissions without generating additional subnet traffic.Cevap
  3. C
    Executing active non-credentialed network vulnerability scans to discover missing host-level patches via port responses.
  4. D
    Configuring inline Web Application Firewalls to block malicious web traffic and report software bugs.
  5. E
    Deploying honeypot systems on production subnets to measure internal server patch compliance.

Cevap

The analyst should implement agent-based credentialed scanning to audit host-level patches and configurations without network probe overhead, along with passive network traffic monitoring to detect unencrypted cleartext data in motion without generating network traffic.
Agent-based credentialed scanning grants direct local access to audit installed patches and OS configurations without sending intrusive network traffic across subnets. Passive network traffic monitoring evaluates network traffic via SPAN/TAP ports to identify unencrypted data without injecting synthetic network probes.

Adım Adım Çözüm

1
Analyze host patch auditing requirement without network probe overhead.
Agent-based credentialed scanning operates locally on the target operating system, granting complete visibility into installed patches and registry settings while avoiding disruptive network scans.
Satisfies the requirement for internal patch auditing without high network traffic impact.
2
Analyze unencrypted data transmission requirement without injecting network probes.
Passive network traffic monitoring passively inspects packet headers and payloads from SPAN/TAP ports, identifying unencrypted protocols in transit without generating synthetic probes.
Satisfies the requirement to observe cleartext sensitive data without affecting network traffic.
3
Evaluate and eliminate incorrect distractor options.
Active non-credentialed scanning sends intrusive probes, web application firewalls are inline preventive controls rather than assessment techniques, and honeypots are deception tools rather than assessment tools.
Eliminates techniques that either inject probes, misclassify control types, or misuse deception tech.

Anahtar Kavram

Selecting appropriate credentialed, non-intrusive, and passive security assessment methodologies based on operational constraints.
Tahmini Süre:2m 0s
Bu soruyu puanla