Security scan results may provide with a false sense of security

​Security scanning results will show what only those results where security scanning host had access to.

For example a system maybe running a vulnerable version of mail software, but access to mail protocols is prevented at the firewall level.

Security scanning results in such a case will result in “all clear”, where in reality there is a problem.

Security scanning hosts will need to have proper access to network or hosts that they scan.

If network is segmented into several subnetworks, and these subnetworks limit network traffic, then consider implementing a security scan per network segment, or work with your network administrators to allow unrestricted network traffic from security scanning host.

YouTube video

Comments

Popular posts from this blog

Absolute and relative path in HTML pages

Errors

goto PHP operator