Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementMedium
A security team is preparing to conduct a vulnerability scan on a production environment. To minimize potential disruption to critical services, they decide to use a non-intrusive scanning approach. Which of the following best describes the characteristics of such a scan?
- AIt requires agents to be installed on target systems for deeper analysis.
- BIt attempts to exploit identified vulnerabilities to confirm their existence.
- CIt performs a full port scan on all 65535 ports to identify open services.
- DIt primarily relies on banner grabbing and version checks without sending malicious payloads.
Show answer & explanationAnswer & explanation
Correct answer: D. It primarily relies on banner grabbing and version checks without sending malicious payloads.
A non-intrusive scan aims to identify vulnerabilities without actively exploiting them or causing service disruption. This typically involves passive checks like banner grabbing, version identification, and configuration analysis.
Why the other options are wrong
- A. While agent-based scanning can be thorough, it's about the deployment method, not necessarily the intrusiveness level. Agentless scans can also be non-intrusive.
- B. This describes an intrusive scan or penetration testing, which is explicitly what they want to avoid.
- C. A full port scan is generally considered intrusive due to the volume of network traffic it generates, which can impact performance or trigger security alerts.
Non-Intrusive Scan
A type of vulnerability scan that identifies potential weaknesses without actively exploiting them or causing disruption to systems.
- Focuses on information gathering, not exploitation.
- Safer for production environments.
- May result in more false positives than intrusive scans.
Memory trick: Non-intrusive scans are like a careful librarian, checking books without tearing pages.