CAS-003 · Question #546
There have been several exploits to critical devices within the network. However, there is currently no process to perform vulnerability analysis. Which the following should the security analyst…
The correct answer is B. Vulnerability scanning frequency that does not interrupt workflow. During production hours, vulnerability scanning must be tuned to a frequency and intensity that identifies threats without disrupting normal business operations.
Question
There have been several exploits to critical devices within the network. However, there is currently no process to perform vulnerability analysis. Which the following should the security analyst implement during production hours to identify critical threats and vulnerabilities?
Options
- Aasset inventory of all critical devices
- BVulnerability scanning frequency that does not interrupt workflow
- CDaily automated reports of exploited devices
- DScanning of all types of data regardless of sensitivity levels
How the community answered
(48 responses)- A10% (5)
- B81% (39)
- C2% (1)
- D6% (3)
Why each option
During production hours, vulnerability scanning must be tuned to a frequency and intensity that identifies threats without disrupting normal business operations.
An asset inventory catalogs what exists on the network but does not actively detect or analyze vulnerabilities and threats.
Configuring vulnerability scanning frequency to avoid workflow disruption allows continuous risk visibility while keeping production systems available and performant. A scanner set to low-impact scheduling or off-peak timing balances the need to detect critical vulnerabilities with the operational requirement to avoid service degradation. This directly addresses the lack of a vulnerability analysis process without introducing new risk to production availability.
Automated reports of already-exploited devices are reactive and provide after-the-fact information rather than proactively identifying threats before exploitation occurs.
Scanning all data regardless of sensitivity is inefficient, may violate data handling policies, and does not specifically address identifying critical threats.
Concept tested: Vulnerability scanning frequency during production operations
Source: https://www.nist.gov/publications/technical-guide-information-security-testing-and-assessment
Topics
Community Discussion
No community discussion yet for this question.