"Vulnerability scanning is best described by which of the following? Question 8 options: Should be conducted before any other scanning efforts. Provides a list of hosts on a specific network. Identifies potential attack vectors on a target system. None of the above"
Added by Carl T.
Step 1
Step 1: Understand what vulnerability scanning does. Show more…
Show all steps
Your feedback will help us improve your experience
Akash M and 91 other AP CS educators are ready to help you.
Ask a new question
Labs
Want to see this concept in action?
Explore this concept interactively to see how it behaves as you change inputs.
Key Concepts
Recommended Videos
On a Thursday afternoon, a network intrusion detection sensor records vulnerability scanning activity directed at internal hosts that is being generated by an internal IP address. Because the intrusion detection analyst is unaware of any authorized, scheduled vulnerability scanning activity, she reports the activity to the incident response team. When the team begins the analysis, it discovers that the activity has stopped and that there is no longer a host using the IP address. The following are additional questions for this scenario: 1. What data sources might contain information regarding the identity of the vulnerability scanning host? 2. How would the team identify who had been performing the vulnerability scans? 3. How would the handling of this incident differ if the vulnerability scanning were directed at the organization's most critical hosts? 4. How would the handling of this incident differ if the vulnerability scanning were directed at external hosts? 5. How would the handling of this incident differ if the internal IP address was associated with the organization's wireless guest network? 6. How would the handling of this incident differ if the physical security staff discovered that someone had broken into the facility half an hour before the vulnerability scanning occurred?
Akash M.
Reconnaissance: Download and install the Nmap port scanner. Find tutorials for Nmap on their site, your book, and other resources on the web and keep them handy. Understand what you are about to do first! a. Run at least three different scans on your computer (set localhost as target). b. Run a scan on scanme.nmap.org as target. What key differences do you see in the results on your machine vs nmap.org? Research and explain the differences. Reconnaissance: Jane has an intent to penetrate the network in an organization. She has used passive reconnaissance to gather extensive information on the company. She finds out the model numbers of routers and other devices by reading discussions between system administrators in forums. She also has a list of all the IT staff and their phone numbers. She also has the services running on ports on some machines she ran a network scanner on. What reasonable steps should the company have taken to prevent Jane from finding this information? What steps should the company take to prevent or reduce the efficacy of port scans?
Supreeta N.
Title: RaptorX Attacks! Scenario: The notorious hacker RaptorX is looking to make a splash by targeting your organization for an attack. He is currently looking for weaknesses in your organization's security as you begin this assignment. RaptorX typically takes two approaches to attacking a network: 1. Going through the "front door" using network-based attacks. 2. Finding a shortcut to the inside of the network using social engineering. Once he has a foothold on an internal network, he installs malicious software designed to search the network for valuable information and send it to a series of IP addresses in Eastern Europe. You have done your homework and convinced your organization to implement the following three security components: 1. Active IDS (also called an IPS) 2. Stateful Packet Inspection Firewall 3. Virus scanner Determinations: Briefly describe how each security component could play a role in stopping each of the two attack approaches. Active IDS (4 points): Stateful Packet Inspection Firewall (4 points): Virus scanner (4 points): Can any one of the security components alone stop either of the approaches RaptorX will take to attack the network? (3 points) If so, which one(s)? If not, why not? Write a brief memo to the management team of your organization stating the importance of using a layered security approach with security components. (5 points)
Recommended Textbooks
Computer Science and Information Technology
Introduction to Programming Using Python
Computer Science - An Overview
Transcript
Watch the video solution with this free unlock.
EMAIL
PASSWORD