In: Computer Science
A security analyst is reviewing output from a CVE-based
vulnerability scanner. Before
conducting the scan, the analyst was careful to select only
Windows-based servers in a specific
datacenter. The scan revealed that the datacenter includes 27
machines running Windows 2003
Server Edition (Win2003SE). In 2015, there were 36 new
vulnerabilities discovered in the Win2003SE
environment. Which of the following statements are MOST likely
applicable? (Choose two.)
A. Remediation is likely to require some form of compensating
control.
B. Microsoft's published schedule for updates and patches for
Win2003SE have continued
uninterrupted.
C. Third-party vendors have addressed all of the necessary updates
and patches required by
Win2003SE.
D. The resulting report on the vulnerability scan should include
some reference that the scan of the
datacenter included 27 Win2003SE machines that should be scheduled
for replacement and
deactivation.
E. Remediation of all Win2003SE machines requires changes to
configuration settings and
compensating controls to be made through Microsoft Security
Center's Win2003SE Advanced
Configuration Toolkit.
Please explain for thumbs up.
Answer: (D) and (E)
(D) The resulting report on the vulnerability scan should include some reference that the scan of the datacenter included 27 Win2003SE machines that should be scheduled for replacement and deactivation.
(E) Remediation of all Win2003SE machines requires changes to configuration settings and compensating controls to be made through Microsoft Security Center's Win2003SE Advanced Configuration Toolkit.
Description:
• Common vulnerabilities and exposure CVE based scanner gives the information report about system vulnerabilities and its security issues. CVE scanner relies on freely accessible system data.
• The CVE scanner provides common interface to evaluate various security tools and make impactful database information. CVE reports provide the every detail about vulnerability issues, system risk level and its impact on environment along with the solutions.
• So, when security analyst scanned the output from a CVE-based scanner then that resulting report on vulnerabilities and exposure scan must include information about 27 Win2003SE machines with the datacenter which were scheduled for the replacement procedure or the deactivation.
• Solution for new found vulnerabilities includes changes in configuration settings that can be done using Win2003SE Advanced Configuration Toolkit of Microsoft Security MS - Center.