exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 121 discussion

Actual exam question from CompTIA's CS0-003
Question #: 121
Topic #: 1
[All CS0-003 Questions]

A company is deploying new vulnerability scanning software to assess its systems. The current network is highly segmented, and the networking team wants to minimize the number of unique firewall rules. Which of the following scanning techniques would be most efficient to achieve the objective?

  • A. Deploy agents on all systems to perform the scans
  • B. Deploy a central scanner and perform non-credentialed scans
  • C. Deploy a cloud-based scanner and perform a network scan
  • D. Deploy a scanner sensor on every segment and perform credentialed scans
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 1 year, 5 months ago
Selected Answer: A
This ones tough. D can be a good answer but I actually think this is A. If its that segmented and they want to minimize firewall rules, deploying a scanner sensor on every segment doesn't seem practical. It specifically says they're assessing systems, and if the option to deploy the agent directly to the systems is there, then it is less resource heavy and less maintenance to do an agent-based discovery.
upvoted 12 times
...
7167087
Most Recent 3 months, 2 weeks ago
Selected Answer: A
It's not D. Key to eliminate it is credentialed scans, you often need to make exceptions in firewall rules for credentialed scans. B would need access to all network segments which would mean extensive firewall modifications.
upvoted 1 times
...
cy_analyst
6 months, 3 weeks ago
Selected Answer: A
Deploy a scanner sensor on every segment and perform credentialed scans: While this is a good approach for thorough scanning, deploying scanners on every segment increases the complexity and would likely require multiple firewall rules for communication between the scanner and the systems in each segment.
upvoted 1 times
...
BanesTech
1 year ago
Selected Answer: D
Option A, deploying agents on all systems to perform the scans, may be effective in some environments but can be resource-intensive and complex to manage, especially in highly segmented networks. Overall, Option D, deploying scanner sensors on every segment and performing credentialed scans locally, is the most efficient approach to minimizing the number of unique firewall rules while effectively scanning a highly segmented network.
upvoted 3 times
BanesTech
1 year ago
Option D is incorrect as well. Deploying a scanner sensor on every segment and performing credentialed scans would require a significant number of firewall rules to allow communication between each sensor and the central management console. This approach could result in a complex and difficult-to-maintain firewall rule set, which contradicts the objective of minimizing unique firewall rules. The Option is B.
upvoted 2 times
...
...
section8santa
1 year ago
Selected Answer: A
This method involves installing scanning agents directly on the systems to be scanned. The agents can perform the scans locally and then report the results back to a central management server. This approach significantly reduces the need for extensive firewall rule configurations because the scanning traffic doesn't have to traverse the network segments. The communication between the agents and the central server can be streamlined, requiring minimal firewall rule changes.
upvoted 4 times
...
CyberJackal
1 year, 1 month ago
Selected Answer: D
This one is D in my opinion. As I read the question, the organization has already selected the software they are intending to use, and it will be a traditional network-based scanner. Often times in segmented environments, explicit firewall rules will need to be implemented to ensure the scanner isn't blocked by IPS as it conducts it's scan across hosts in other VLANs- or scanner sensors are deployed in said target VLANs. That's what they're getting at- is to have you come to that conclusion here, though like many questions from CompTIA it should be worded better or remove the agent option from potential answers.
upvoted 1 times
...
MMK777
1 year, 1 month ago
Selected Answer: D
we had the same scenario in the company where I work and we deployed a scanner sensor on every segment of the network.
upvoted 1 times
...
deeden
1 year, 5 months ago
Selected Answer: A
I believe there is a slight difference in creating FW rules for: A. agent plug-in installed on existing IP, versus D. new sensors deployed on each segment. The first one you'll only need to allow the Manager node and port from the corporate supernet, versus allowing scanner to each sensor on each vlan. However, as this is convenient to the network team, it's a significant work for the security/system administrator to maintain each agent, unless through automation.
upvoted 1 times
...
[Removed]
1 year, 5 months ago
Selected Answer: A
Going with A on this one. Better option than D since the question states it's "high segmented", so deploying a scanner sensor on every segment would be a lot of work.
upvoted 2 times
bmadajczyk
1 year, 4 months ago
A bit tricky one but agree on the take. A is the correct answer
upvoted 1 times
...
...
VVV4WIN
1 year, 5 months ago
We know little about the software. Both D and A can be argued that it will require the same amount of firewall rules, which is potentially none in the case that every agent/scanner sensor is checked directly for the results of the scans. Alternatively (and more likely), the info is sent to some management server after the scans are completed, which will mean an additional rule is added to the firewalls for every segment to allow either the agents of every segment or the scanner sensor of every segment to communicate the results back to the server. In both these cases, no other firewall rules will need to be opened as the scanners are already on each segment, very very tricky question. Comes down to that silly rhetorical question: "how long is a piece of string?"
upvoted 1 times
...
chaddman
1 year, 6 months ago
Deploy agents on all systems to perform the scans (A): Agent-based scanning would be the most efficient for minimizing firewall rules because the agents would reside on each system, negating the need for network traffic to traverse the segmented network for scanning purposes. This minimizes the need for creating additional firewall rules to allow scan traffic.
upvoted 1 times
...
kmordalv
1 year, 8 months ago
Selected Answer: D
Correct Deploying a scanner sensor on every segment allows for localized scanning within each segment, which can significantly reduce the need for complex and unique firewall rules. Credentialed scans involve using valid credentials (such as usernames and passwords) to assess the systems. This allows the scanner to gather more accurate and detailed information about vulnerabilities, software versions, and configurations without relying on excessive open ports that might be required for non-credentialed scans.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago