From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 22,600 courses taught by industry experts.

Scan perspective

Scan perspective

- [Narrator] All vulnerability scans are not alike. While you may set scans to test the same systems using the same tool on the same ports and services, there are other factors that may affect what you see in your scan results. Let's talk about scan perspective. The most important component of scan perspective is the scanner's location on the network relative to the systems being scanned. For example, consider this typical network diagram showing a firewall that connects an organization to the internet and also segments of DMZ that contains a web server accessible to the outside world. If as in this diagram, the vulnerability scanner is also in the DMZ, the scanner has unrestricted access to the web server because it doesn't need to pass through the firewall to get there. However, if the vulnerability scanner is instead located on the internal network, we have a totally different picture. Now, the vulnerability scanner's traffic must pass through the firewall on the way to the web…

Contents