How can you limit breadth and scope of a vulnerability scan

Assignment Help Computer Engineering
Reference no: EM131152977

Lab- Performing a Vulnerability Assessment

Overview

In this lab, you used Nmap commands within the Zenmap application to scan the virtual network and identify the devices on the network and the operating systems and services running on them. You also used OpenVAS to conduct a vulnerability assessment and record the high risk vulnerabilities identified by the tool. Finally, you used the information you gathered from the report to discover mitigations for those risks and make mitigation recommendations based on your findings.

Lab Assessment Questions & Answers

1. What is Zenmap typically used for? How is it related to Nmap? Describe a scenario in which you would use this type of application.

2. Which application can be used to perform a vulnerability assessment scan in the reconnaissance phase of the ethical hacking process?

3. What must you obtain before you begin the ethical hacking process or penetration test on a live production network, even before performing the reconnaissance step?

4. What is a CVE listing? Who hosts and sponsors the CVE database listing Web site?

5. Can Zenmap detect which operating systems are present on IP servers and workstations? Which option includes that scan?

6. How can you limit the breadth and scope of a vulnerability scan?

7. Once a vulnerability has been identified by OpenVAS, where would you check for more information regarding the identified vulnerability, exploits, and any risk mitigation solution?

8. What is the major difference between Zenmap and OpenVAS?

9. Why do you need to run both tools like Zenmap and OpenVAS to complete the reconnaissance phase of the ethical hacking process?

Reference no: EM131152977

Questions Cloud

Could americans make such adjustments : How could the surveillance society liberate a culture from antiquated norms or push cultural consensus toward a new morality based on actual harm as opposed to group preferences, opinions or traditions?
Significance level for hypothesis testing : A clothing factory needs to determine whether a new machine was producing a breaking strength of 70 pounds and standard deviation of 3.5 pounds. A sample of 36 pieces revealed a sample mean of 69.7 pounds. Is there evidence that the machine is not..
Amount of cash spent without being aware : Consumers spend of $21 per week in cash without being aware of where it goes. Assume that the amount of cash spent without being aware of where it goes is normally distributed and that the Standard Deviation is $5 a.) What is the probability that ..
Purchasing agent of company : As the purchasing agent of your company you are deciding what type of Xerox machine to buy for your company. You have narrowed your choices to brand X and brand Y.
How can you limit breadth and scope of a vulnerability scan : What is a CVE listing? Who hosts and sponsors the CVE database listing Web site? What is Zenmap typically used for? How is it related to Nmap?  How can you limit the breadth and scope of a vulnerability scan?
Container of liquid laundry detergent : A container of liquid laundry detergent promises over 100 loads from the bottle. You sample 45 bottles and find a mean of 102 loads with a standard deviation of 3.75 loads. At the 0.01 level of significance, is the manufacturer's claim supported?
Development of the clients presentation : Investigate and outline the prevalence/incidence of depression AND suicide in Australia - Ensure your answer covers: gender, age groups. Specific risk groups. hospitalization and recovery.
Identify the first step in the student guide to research : Define the basic concepts used in the discipline of sociology. Define the various methodologies for sociological research. Use technology and information resources to research issues in sociology.
Conduct a hypothesis test : She randomly surveys 426 schoolmates and finds that 150 report they fear public speaking. Conduct a hypothesis test at the 5% level of significance to determine if the percent at her school is less than 40%

Reviews

Write a Review

Computer Engineering Questions & Answers

  Transmitting message and tentative checkpoint

Is node P allowed to transmit the messages related to application (as opposed to message which is part of checkpoint algorithm itself) immediately after having taken a tentative checkpoint?

  Suppose that you are working for the business systems

assume that you are working for the business systems analysis department in ibms prc division which offers both

  Program to perform the different arithmetic operations

Write down a Ruby program that continuously reads in the number, x, from the screen, and then computes and displays its: Factorial, if x is less than 15; Fourth power, if 15 35.

  The difference between animation and transition effects

When are they appropriate? When is it better not to use them? Can you give me an examples.

  What is a work breakdown structure

What is  a work breakdown structure

  One-time password scheme

Lamport's one-time password scheme uses the passwords in reverse order. Would it not be simpler to use f (s) the first time, f (f(s)) the second time, and so on?

  Distinguish between open and closed applications.

explain  HTML, XML and Java programming. What is the difference between the three.

  Advances in security of biometrics

Advances in Security of Biometrics - Aims and Objectives: Modern biometrics is defined as the science of using biological properties to identify individuals. Biometrics delivers an enhanced level of security by means of a "proof of property"

  Write a program that inputs an integer for n

Write a program that inputs an integer for n, iterates through the Babylonian algorithm twenty times, and outputs the answer as a double to two decimal places. Your answer will be most accurate for small values of n.

  Research the firm and its industry environment

Select a realfirm as the focus of your report. This can be a pure-play internet company, or a traditional firm that is engaged in eBusiness activities.

  A non pipeline processor has a clock rate of 25 mhz

A non pipeline processor has a clock rate of 25 MHz and an average CPI of 4. Processor Y, an improved successor of X, is designed with a 5 stage linear instruction pipeline. However due to latch delay and clock skew effects, the clock rate of Y is on..

  Advantages of technologies

List some of the advantages of some of current technologies explained in our reading this week involving VoIP, Virtual Private Networks, Unified Communications, Wi-Fi and wireless technologies such as RFID.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd