1 / 5100%
Running Head: Inventory Assets On Network And Identify Vulnerabilities i i i i i i i i i i i i i i i i i i i i i i 1
Inventory Assets on Network and Identify Vulnerabilities
CYB 205 – Infrastructure Administration
Inventory Assets On Network And Identify Vulnerabilities i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 2
• Write a brief description of a vulnerability found in the scan, including the
operating system on which it was found, its risk factor, and its CVSS scores.
One vulnerability found during the advanced scan was the ‘SSL Certificate cannot be trusted.’
It basically implies that the SSL Certificate that exists within the server cannot be trusted.
Such an error can take place when a website uses a self-signed certificate, or the necessary
certificate is not there. The operating system on which the vulnerability was found was the
Windows Operating System (Nyanchama, 2005). The level of the risk factor for such a
vulnerability was ‘medium’ and its Common Vulnerability Scoring System (CVSS) version
3.0 score was 6.5 and its CVSS Base Score was 6.4.
• Are the results of default scans different than the credentialed scan?
The results of the default scans are significantly different in nature as compared to a
credentialed vulnerability scans. Default scan fundamentally provides an insight into the
vulnerabilities that are found within the network services that are exposed by the host. On the
other hand, the credentialed scan gives a comprehensive insight into the situation (Jajodia &
Noel, 2010). This is because credentialed scans provide a significant amount of details and
include an observation of the operating system as well as the application vulnerabilities and
the vulnerabilities that exist behind a firewall. Thus, the results of default scans and
credentialed vulnerability scans are very different from one another and they give a different
degree of insight into a threat.
• What types of vulnerabilities might an attacker without any credentials be able to
identify and exploit?
By simply using a scan, an attacker would be able to attack and exploit a network even if he
does not have any credentials. An attacker basically has the opportunity to compromise the
Inventory Assets On Network And Identify Vulnerabilities i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 3
security of a network by exploiting diverse elements such as insider threats, weak passwords,
formerly compromised accounts as well as the lack of necessary protection against social
engineering (Nyanchama, 2005). These vulnerabilities could be exploited by an attacker in
order to successfully gain access into a network system. Once these unauthorized actors gain
access into the network, they would be able to view vital and sensitive information relating to
the business and/or its clients. The attacker can still go after open ports and services on the
server, such as TCP Ports 80 and 443 on a web server.After gaining access into the
Information Technology (IT) ecosystem of a business entity, cybercriminals could combine a
broad range of attacks for the purpose of exploiting anything that exists within the system of
the organization.
• This was a simple 3-computer LAN. How much more complicated would this
process be for 100 computers? What about an enterprise with 10,000 computers
on their LAN/WAN?
A number of complications could arise in the vulnerability scan process for a large enterprise
network with more than 1000 computers as opposed to a small 3 computer network. The
biggest concerns that would arise for the large enterprise network revolves around security
issues, performance-related complexities and host identification concerns. The existence of
close to 1000 computer systems could have a direct implication on the performance of the
LAN/WAN. This is because the performance could slow down and the data integrity could
also be compromised due to the high distance between the endpoints and the midpoints. The
proper configuration of routers, controllers as well as switches would be a fundamental
necessity that could impact their performance. The larger the size of the network system, the
more number of users would be operating on it. Thus it could lead to a higher level of points of
access. It could intensify the overall security risks and challenges relating to insider threats,
the use of weaker passwords, and unauthorized access into the system (Nyanchama, 2005). i
Inventory Assets On Network And Identify Vulnerabilities i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 4
• Consider a cloud-hosted Infrastructure as a Service (IaaS) environment with
many new, internet-accessible systems regularly being built and brought online.
What advantages or challenges might there be with regard to vulnerability
management in the cloud?
The main challenge associated with Vulnerability Management while considering a cloud-
based Infrastructure as a Service (IaaS) relates to the lack of proper control. In the cloud-based
landscape, a third party is responsible for handling and maintaining of physical servers, and
providing patches, configurations and updates. Due to the involvement of the third party in the
security aspects, the client organization is not able to have any control over the security
aspects relating to unauthorized access or the loss of data.
References
Inventory Assets On Network And Identify Vulnerabilities i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i 5
Jajodia, S., & Noel, S. (2010). Topological vulnerability analysis. In Cyber situational
awareness (pp. 139-154). Springer, Boston, MA.
Nyanchama, M. (2005). Enterprise Vulnerability Management and Its Role in Information
Security Management. Inf. Secur. J. A Glob. Perspect., 14(3), 29-56.
Students also viewed