GPEN · Question #454
You are performing a vulnerability assessment using Nessus and your clients printers begin printing pages of random text and showing error messages. The client is not happy with the situation. What…
The correct answer is B. Ensure Safe Checks is enabled in Nessus scan policies. Enabling Safe Checks in Nessus prevents disruptive plugins from running against sensitive devices like printers, which can cause erratic behavior during vulnerability scans.
Question
You are performing a vulnerability assessment using Nessus and your clients printers begin printing pages of random text and showing error messages. The client is not happy with the situation. What is the best way to proceed?
Options
- AEnable the "Skip all primers" option and re-scan
- BEnsure Safe Checks is enabled in Nessus scan policies
- CRemove primer IP addresses from your target list
- DVerify primers are in scope and tell the client In progress scans cannot be stopped
How the community answered
(27 responses)- A7% (2)
- B78% (21)
- C4% (1)
- D11% (3)
Why each option
Enabling Safe Checks in Nessus prevents disruptive plugins from running against sensitive devices like printers, which can cause erratic behavior during vulnerability scans.
There is no 'Skip all primers' option in Nessus scan policies - this is a fabricated setting that does not exist in the product.
Safe Checks is a Nessus scan policy setting that disables plugins deemed potentially harmful to fragile or production-critical devices such as printers, embedded systems, and older network hardware. When enabled, Nessus relies on banners and non-destructive checks rather than active exploitation-style probes. This is the recommended best practice when scanning environments where device disruption is unacceptable.
Removing printer IPs from the target list is a one-time workaround for this scan but does not fix the underlying scan policy issue, and those devices may be legitimately in scope.
Nessus scans can be paused or stopped at any time; telling the client otherwise is factually incorrect and professionally inappropriate.
Concept tested: Nessus Safe Checks policy for non-disruptive scanning
Source: https://docs.tenable.com/nessus/Content/ScanSettings.htm
Topics
Community Discussion
No community discussion yet for this question.