Which approach involves limiting scans to ports approved by the firewall configuration, but may be invasive and not assess firewall failures?

Study for the SANS560 GIAC Penetration Tester (GPEN) Test. Study with flashcards and multiple choice questions, each question has hints and explanations. Get ready for your exam!

Multiple Choice

Which approach involves limiting scans to ports approved by the firewall configuration, but may be invasive and not assess firewall failures?

Explanation:
Limiting the scan to ports that the firewall configuration explicitly approves is a practical way to manage large assessments. By sticking to only those ports, you respect the security policy and reduce noise and time spent on scanning, which helps you stay within approved boundaries. This approach is considered invasive because you’re actively probing services within the allowed ports, potentially stressing those services or triggering alerts, even though you’re not touching every possible port. However, it won’t reliably reveal firewall failures, since you aren’t testing how traffic is handled on ports that are blocked or dropped by the firewall. In contrast, a full port sweep would probe every port, and the other options describe general strategies for handling large scans without specifically tying the scope to firewall-approved ports.

Limiting the scan to ports that the firewall configuration explicitly approves is a practical way to manage large assessments. By sticking to only those ports, you respect the security policy and reduce noise and time spent on scanning, which helps you stay within approved boundaries. This approach is considered invasive because you’re actively probing services within the allowed ports, potentially stressing those services or triggering alerts, even though you’re not touching every possible port. However, it won’t reliably reveal firewall failures, since you aren’t testing how traffic is handled on ports that are blocked or dropped by the firewall. In contrast, a full port sweep would probe every port, and the other options describe general strategies for handling large scans without specifically tying the scope to firewall-approved ports.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy