CISM · Question #827
Which of the following is the BEST way for an organization to compensate for slowdowns in production network performance due to vulnerability scanning?
The correct answer is A. Perform vulnerability scanning after business hours. Scheduling vulnerability scans after business hours eliminates the conflict between scanning traffic and production workloads, preserving network performance during critical business periods without compromising the security program. Restricting packet scope (C) may reduce scan…
Question
Which of the following is the BEST way for an organization to compensate for slowdowns in production network performance due to vulnerability scanning?
Options
- APerform vulnerability scanning after business hours.
- BConduct unannounced penetration tests after business hours.
- CRestrict the scope of vulnerability scanning packets to be released to the network.
- DDiscontinue vulnerability scanning and apply patches to high-risk areas.
How the community answered
(48 responses)- A81% (39)
- B10% (5)
- C2% (1)
- D6% (3)
Explanation
Scheduling vulnerability scans after business hours eliminates the conflict between scanning traffic and production workloads, preserving network performance during critical business periods without compromising the security program. Restricting packet scope (C) may reduce scan effectiveness and miss vulnerabilities. Discontinuing scanning and only patching high-risk areas (D) is dangerous and leaves unknown vulnerabilities undetected. Unannounced penetration tests (B) are a different activity altogether with a different purpose and risk profile. Scheduling is the simplest, least disruptive, and most effective operational control for this specific problem.
Topics
Community Discussion
No community discussion yet for this question.