adplus-dvertising
frame-decoration

Question

What does Control Enhancement 3 for vulnerability scanning procedures entail under FISMA?

a.

Identifying information system vulnerabilities

b.

Updating information system vulnerabilities prior to a new scan

c.

Determining discoverable information by adversaries

d.

Identifying multi-vulnerability/multi-hop attack vectors

Answer: (c).Determining discoverable information by adversaries Explanation:Control Enhancement 3 involves employing vulnerability scanning procedures that can identify the breadth and depth of coverage, including information system components scanned and vulnerabilities checked.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. What does Control Enhancement 3 for vulnerability scanning procedures entail under FISMA?

Similar Questions

Discover Related MCQs

Q. Why were Control Enhancements 7 and 9 withdrawn by NIST?

Q. Why do many organizations mandate vulnerability scanning in their corporate policy, even if it is not a regulatory requirement?

Q. How do penetration testers use vulnerability scans in support of their testing efforts?

Q. In what scenario might penetration testers conduct vulnerability scans focused on known IoT vulnerabilities?

Q. What factors are considered in the planning process to identify systems covered by vulnerability scans?

Q. How do cybersecurity professionals use automated techniques to identify systems for vulnerability scans?

Q. What does asset inventory and criticality information help determine in the context of vulnerability scanning?

Q. Why do administrators often configure vulnerability scans to produce automated email reports?

Q. What type of access do penetration testers typically require for vulnerability scanning consoles?

Q. How does an organization's risk appetite influence the frequency of vulnerability scans?

Q. What may dictate a minimum frequency for vulnerability scans?

Q. Why might business constraints impact the frequency of vulnerability scans?

Q. What is a recommended approach for organizations when planning a vulnerability scanning program?

Q. What is a potential drawback of active vulnerability scanning?

Q. What is a risk associated with active vulnerability scanning, even with minimized settings?

Q. What may active scanning potentially miss?

Q. How does passive vulnerability scanning differ from active scanning?

Q. What do passive scanners look for in network traffic?

Q. What is the primary purpose of scoping in vulnerability scans?

Q. What should administrators ensure before configuring vulnerability scans within the vulnerability management tool?