GCIH · Question #580
An analyst ran a Nessus scan with Dangerous plugins enabled for performing a vulnerability scan against a business critical system running on the production network. This brought down the target…
The correct answer is B. Scan the business critical systems, after you disable dangerous plugins. Dangerous plugins in Nessus are NOT enabled by default, especially to perform a complete scan and definitely not used with a specific goal of bringing down the target host. There are dangerous plugins in Nessus and if enabled that could perform attacks on the target box and…
Question
An analyst ran a Nessus scan with Dangerous plugins enabled for performing a vulnerability scan against a business critical system running on the production network. This brought down the target host, without alerting on it while the scan was occurring. How could the scan have avoided crashing the target host?
Options
- ANever scan production networks, since they are business critical at all times
- BScan the business critical systems, after you disable dangerous plugins
- CDo not scan any business critical systems, since they have other priorities
- DUse a different vulnerability scanner, since Nessus is dangerous in this situation
How the community answered
(50 responses)- A2% (1)
- B78% (39)
- C14% (7)
- D6% (3)
Explanation
Dangerous plugins in Nessus are NOT enabled by default, especially to perform a complete scan and definitely not used with a specific goal of bringing down the target host. There are dangerous plugins in Nessus and if enabled that could perform attacks on the target box and Denial of Service the target by actually launching the attack. Denial of Service (DoS) should not be run against a business critical production host that is currently being use, because Dangerous plugins which performs DoS on the host along with various active attacks could bring the target down. Choosing to not scan business critical systems is not an option, since you need to know what is vulnerable in order to fix it. Using a different vulnerability scanner is not going to keep the business critical systems up and running, since that has nothing to do with the given problem. If you are not going to scan production networks, there is no way to find vulnerabilities and patch them. Here, the real issue is Dangerous Plugins in Nessus being enabled by the analyst and the fix for this is to disable dangerous plugin before scanning business critical systems.
Topics
Community Discussion
No community discussion yet for this question.