CSIS 330 – Lab 6: Identifying Security
Vulnerabilities Answer Template
Questions:
5. a. They take advantage of systems that are not up-to-date and do not have tighter
security.
b. By keeping all systems connected to a network updated so that the latest
versions of security are applied to the system’s inventory.
c. Maintaining an asset inventory of all systems connected to the network and
the network devices themselves, recording at least the network addresses, machine names,
purpose of each system, an asset owner responsible for each device, and the department
associated with each device.
d. Active and passive device scanning, storing databases offline, alert security
systems, and security defenders monitor and secure inventory database.
e. Systems that are capable of identifying unauthorized software by detecting
either an attempt to install or execute it. Also, these systems need to be able to block said
software.
6. a. Major thefts of data have been initiated by attackers who have gained wireless
access to organizations from outside the physical building, bypassing organizations’ security
perimeters by connecting wirelessly to access points inside the organization.
b. Ensure that each wireless device connected to the network matches an
authorized configuration and security profile, with a documented owner of the connection
and a defined business need. Organizations should deny access to those wireless devices that
do not have such a configuration and profile.
c. Where a specific business need for wireless access has been identified,
configure wireless access on client machines to allow access only to authorized wireless
networks.
d. Effective organizations run commercial wireless scanning, detection, and
discovery tools as well as commercial wireless intrusion detection systems.
e. A wireless client with an unauthorized service set identifier configured on it.