1
1

00:00:00,150  -->  00:00:02,040
<v ->In this section of the course, we're going to cover</v>
2

2

00:00:02,040  -->  00:00:05,160
how to analyze output from vulnerability scans.
3

3

00:00:05,160  -->  00:00:06,780
Now, we're going to stay in Domain 2,
4

4

00:00:06,780  -->  00:00:08,130
vulnerability management,
5

5

00:00:08,130  -->  00:00:10,800
and go back to Domain 4, reporting and communication,
6

6

00:00:10,800  -->  00:00:12,180
in this section of the course
7

7

00:00:12,180  -->  00:00:13,410
and, here, we're going to be focused on
8

8

00:00:13,410  -->  00:00:14,880
multiple different objectives,
9

9

00:00:14,880  -->  00:00:18,960
including Objectives 2.1, 2.3, and 4.1.
10

10

00:00:18,960  -->  00:00:21,660
Now, Objective 2.1 states that, given a scenario,
11

11

00:00:21,660  -->  00:00:22,920
you must be able to implement
12

12

00:00:22,920  -->  00:00:25,590
vulnerability scanning methods and concepts.
13

13

00:00:25,590  -->  00:00:28,260
Objective 2.3 states that, given a scenario,
14

14

00:00:28,260  -->  00:00:29,760
you must be able to analyze data
15

15

00:00:29,760  -->  00:00:31,710
to prioritize vulnerabilities.
16

16

00:00:31,710  -->  00:00:33,390
And Objective 4.1 states
17

17

00:00:33,390  -->  00:00:35,010
that you must be able to explain the importance
18

18

00:00:35,010  -->  00:00:38,040
of vulnerability management reporting and communication.
19

19

00:00:38,040  -->  00:00:39,810
Now, as we move through this section,
20

20

00:00:39,810  -->  00:00:41,340
we're going to be starting out by discussing
21

21

00:00:41,340  -->  00:00:43,830
the contents of a vulnerability scan report.
22

22

00:00:43,830  -->  00:00:44,790
As part of this,
23

23

00:00:44,790  -->  00:00:46,740
we're going to be looking at the common identifiers
24

24

00:00:46,740  -->  00:00:49,980
such as CVEs, NVDs, CWEs,
25

25

00:00:49,980  -->  00:00:54,000
CAPECs, CPEs, and CCEs.
26

26

00:00:54,000  -->  00:00:55,500
Next, we're going to be talking about
27

27

00:00:55,500  -->  00:00:59,310
the common vulnerability scoring system, known as CVSS.
28

28

00:00:59,310  -->  00:01:01,260
Now, these metrics are going to be applied to
29

29

00:01:01,260  -->  00:01:02,820
our given threats and vulnerabilities
30

30

00:01:02,820  -->  00:01:05,730
to help us understand how dangerous they really are.
31

31

00:01:05,730  -->  00:01:08,730
Then, we're going to dive deeper into the CVSS metrics
32

32

00:01:08,730  -->  00:01:11,010
to better understand how you can interpret and utilize
33

33

00:01:11,010  -->  00:01:13,080
these metrics and their scoring data
34

34

00:01:13,080  -->  00:01:14,640
when you're trying to prioritize risk
35

35

00:01:14,640  -->  00:01:16,170
inside of your network.
36

36

00:01:16,170  -->  00:01:17,490
Next, we're going to describe
37

37

00:01:17,490  -->  00:01:19,260
how you can read a vulnerability report
38

38

00:01:19,260  -->  00:01:21,330
to validate the results of your scan.
39

39

00:01:21,330  -->  00:01:22,530
This is going to be important,
40

40

00:01:22,530  -->  00:01:24,360
because you're going to be getting questions on your exam
41

41

00:01:24,360  -->  00:01:27,300
that require you to be able to perform this type of action.
42

42

00:01:27,300  -->  00:01:28,470
Then, we're going to talk about
43

43

00:01:28,470  -->  00:01:30,120
some specific vulnerability scanners
44

44

00:01:30,120  -->  00:01:32,610
like Nessus, OpenVAS, and Qualys,
45

45

00:01:32,610  -->  00:01:34,890
and, after that, we're going to perform a demonstration
46

46

00:01:34,890  -->  00:01:36,630
where we analyze vulnerabilities found
47

47

00:01:36,630  -->  00:01:38,850
while we conduct a vulnerabilities scan together
48

48

00:01:38,850  -->  00:01:40,500
in my lab environment.
49

49

00:01:40,500  -->  00:01:42,270
Finally, we're going to take a short quiz
50

50

00:01:42,270  -->  00:01:44,340
to see what you learned during this section of the course
51

51

00:01:44,340  -->  00:01:46,020
and review each of those quiz questions
52

52

00:01:46,020  -->  00:01:46,950
to ensure you understand
53

53

00:01:46,950  -->  00:01:49,230
why the right answers were truly right.
54

54

00:01:49,230  -->  00:01:50,880
So, let's go ahead and get started
55

55

00:01:50,880  -->  00:01:53,610
analyzing output from vulnerability scans and scanners
56

56

00:01:53,610  -->  00:01:54,720
so you can better understand
57

57

00:01:54,720  -->  00:01:57,330
all the vulnerabilities that exist within your networks
58

58

00:01:57,330  -->  00:01:59,030
during this section of the course.
