ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 42 Topic 5 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 42 Topic 5 Discussion

312-50v13 Exam Topic 5 Question 42 Discussion:
Question #: 42
Topic #: 5

In the process of implementing a network vulnerability assessment strategy for a tech company, the security

analyst is confronted with the following scenarios:

1) A legacy application is discovered on the network, which no longer receives updates from the vendor.

2) Several systems in the network are found running outdated versions of web browsers prone to distributed

attacks.

3) The network firewall has been configured using default settings and passwords.

4) Certain TCP/IP protocols used in the organization are inherently insecure.

The security analyst decides to use vulnerability scanning software. Which of the following limitations of vulnerability assessment should the analyst be most cautious about in this context?


A.

Vulnerability scanning software is limited in its ability to perform live tests on web applications to detect errors or unexpected behavior


B.

Vulnerability scanning software cannot define the impact of an identified vulnerability on different business operations


C.

Vulnerability scanning software is limited in its ability to detect vulnerabilities at a given point in time


D.

Vulnerability scanning software is not immune to software engineering flaws that might lead to serious vulnerabilities being missed


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.