A cybersecurity analyst is tasked with scanning a web application to understand where the scan will go and whether there are URLs that should be denied access prior to more in-depth scanning. Which of the following best fits the type of scanning activity requested?
Discovery scan
A discovery scan is primarily used to map out the structure of a web application and identify all accessible URLs without delving into detailed vulnerability assessment. It helps in understanding the application's layout, potential entry points, and areas that may require further investigation.
Non-credentialed scans do not involve providing any login credentials for the web application. They typically focus on external security checks and do not delve into detailed assessments that require authenticated access to the system.
Discovery scans are specifically designed to map out the web application's structure and identify accessible URLs and endpoints. These scans help in determining the scope of the application and areas that need further scrutiny, making them a suitable choice for the given scenario.
Vulnerability scans are more focused on identifying security weaknesses and potential vulnerabilities within the application. While important for security assessments, vulnerability scans are more in-depth and specific compared to the broader scope of a discovery scan.
Credentialed scans involve providing login credentials for the web application, allowing the scanner to access deeper levels of the system for a more comprehensive security assessment. This type of scan is useful for evaluating internal security controls and configurations.
In this scenario, where the cybersecurity analyst needs to understand the application's layout and identify URLs that may need further scrutiny without performing detailed vulnerability assessments, a discovery scan is the most appropriate type of scanning activity. It provides a high-level overview of the application's structure and helps in determining the initial scope of the security assessment process.
Related Questions
View allAn organization would like to ensure its cloud infrastructure has a ha...
An incident responder was able to recover a binary file through the ne...
An incident response team found IoCs in a critical server. The team ne...
Which of the following best explains the importance of playbooks for i...
A malicious actor has gained access to an internal network by means of...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations