(6) Scheduling Scans and Scan Types Flashcards

1
Q

What do security professionals depend on to help them perform their duties in an efficient, effective way?

A

Security professionals use automation to help them perform their duties efficiently and effectively

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What factors influence how often an org chooses to do vulnerability scans?

A

These factors influence how an org decides to conduct vulnerability scans:

Risk appetite

Regulatory requirements

Performance constraints

Operations contraints

Licensing Limitations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What considerations must cybersecurity admins balance as they perform their duties?

A

Cybersecurity admins must balance how often they conduct scans but should probably begin small when scanning systems and then expand how they do them over time to avoid overwhelming the scanning infrastructure or the system as a whole

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What do most vulnerability scanning tools perform and what are the drawbacks?

A

Most vulnerability scanning tools perform active vulnerability scanning, it comes with some drawbacks:

-Active scanning is noisy and if the admin knows that you’re scanning that might be ok, but if not, it can cause issues

-Active scanning can acidentally break systems as it scans for vulnerabilities, disrupting critical systems

-Active scans may miss some systems if they are protected by firewalls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is passive vulnerability scanning?

A

Passive vulnerability scanning supplements active scans by monitoring the network, looking for obvious signatures of old systems and apps, reporting those results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is helpful to remember about active vs passive scans?

A

Passive scans can only detect issues that show up in network traffic. They are not a replacement for active scans but they are a nice addition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly