1
1

00:00:00,300  -->  00:00:02,190
<v Instructor>Vulnerability reports.</v>
2

2

00:00:02,190  -->  00:00:03,090
In this lesson,
3

3

00:00:03,090  -->  00:00:05,700
we're going to dig into those vulnerability reports
4

4

00:00:05,700  -->  00:00:07,500
and understand a little bit more about them.
5

5

00:00:07,500  -->  00:00:08,610
Now, before we do that,
6

6

00:00:08,610  -->  00:00:10,920
we have to remember that a vulnerability report
7

7

00:00:10,920  -->  00:00:14,160
that is not validated is essentially useless.
8

8

00:00:14,160  -->  00:00:16,410
If I run the scanning tool, and I take that report,
9

9

00:00:16,410  -->  00:00:17,880
and I hand it into my boss,
10

10

00:00:17,880  -->  00:00:19,680
that doesn't do my boss any good
11

11

00:00:19,680  -->  00:00:21,990
because that report has not been validated.
12

12

00:00:21,990  -->  00:00:23,430
Nobody has looked through it to see,
13

13

00:00:23,430  -->  00:00:25,080
is it actually accurate?
14

14

00:00:25,080  -->  00:00:27,000
All we've done is trust the system.
15

15

00:00:27,000  -->  00:00:29,340
And our job as analysts is to look at these reports
16

16

00:00:29,340  -->  00:00:30,720
and validate them.
17

17

00:00:30,720  -->  00:00:31,590
Now, when we do that,
18

18

00:00:31,590  -->  00:00:33,540
we are looking to look at each of those things
19

19

00:00:33,540  -->  00:00:34,920
that are found in that report
20

20

00:00:34,920  -->  00:00:37,560
and identify them as one of four categories.
21

21

00:00:37,560  -->  00:00:41,700
Are they a true positive, a false positive, a true negative,
22

22

00:00:41,700  -->  00:00:43,050
or a false negative?
23

23

00:00:43,050  -->  00:00:44,880
Now, you may not understand what all of these are,
24

24

00:00:44,880  -->  00:00:46,320
but if you've taken Security+,
25

25

00:00:46,320  -->  00:00:49,020
these concepts should be familiar with you.
26

26

00:00:49,020  -->  00:00:52,230
Now, for many students, this is an area that confuses them.
27

27

00:00:52,230  -->  00:00:53,580
They don't understand the difference
28

28

00:00:53,580  -->  00:00:55,080
between these four categories,
29

29

00:00:55,080  -->  00:00:56,973
and it's really important that you understand them.
30

30

00:00:56,973  -->  00:00:59,460
Now, I covered this in-depth in Security+,
31

31

00:00:59,460  -->  00:01:01,110
but I'm going to go through it again here
32

32

00:01:01,110  -->  00:01:03,360
because it really is an important concept.
33

33

00:01:03,360  -->  00:01:04,680
In fact, on the exam,
34

34

00:01:04,680  -->  00:01:06,300
they may give you some issues,
35

35

00:01:06,300  -->  00:01:07,740
some things from a security report,
36

36

00:01:07,740  -->  00:01:10,500
and ask you to classify them as true positive,
37

37

00:01:10,500  -->  00:01:13,047
false positive, true negative, or false negative.
38

38

00:01:13,047  -->  00:01:14,700
And if you don't understand the concepts,
39

39

00:01:14,700  -->  00:01:16,470
you're not going to be able to get that right.
40

40

00:01:16,470  -->  00:01:18,030
So let's talk about them.
41

41

00:01:18,030  -->  00:01:19,530
First, true positive.
42

42

00:01:19,530  -->  00:01:21,360
What is a true positive?
43

43

00:01:21,360  -->  00:01:23,940
Well, this is an alert that matches a vulnerability
44

44

00:01:23,940  -->  00:01:26,280
and that vulnerability actually exists
45

45

00:01:26,280  -->  00:01:27,900
on the system you scanned.
46

46

00:01:27,900  -->  00:01:30,300
So this is something that really happened.
47

47

00:01:30,300  -->  00:01:31,470
So what I like to think about
48

48

00:01:31,470  -->  00:01:33,120
when I think about these four categories is
49

49

00:01:33,120  -->  00:01:34,590
I like to think about pregnancy,
50

50

00:01:34,590  -->  00:01:36,330
because if you're married
51

51

00:01:36,330  -->  00:01:37,710
and you've tried to have kids before,
52

52

00:01:37,710  -->  00:01:39,900
you probably have gone through taking a pregnancy test
53

53

00:01:39,900  -->  00:01:40,890
at some point in your life,
54

54

00:01:40,890  -->  00:01:42,780
either you or your spouse has.
55

55

00:01:42,780  -->  00:01:44,880
For me, it was my spouse who had to take them.
56

56

00:01:44,880  -->  00:01:46,470
But the same concept is there.
57

57

00:01:46,470  -->  00:01:47,520
And so if we look at that,
58

58

00:01:47,520  -->  00:01:49,350
it makes it really easy to understand.
59

59

00:01:49,350  -->  00:01:51,330
For instance, I have two children.
60

60

00:01:51,330  -->  00:01:53,250
That means at least twice in my life,
61

61

00:01:53,250  -->  00:01:55,290
my wife had taken a pregnancy test
62

62

00:01:55,290  -->  00:01:56,490
and she showed me the results,
63

63

00:01:56,490  -->  00:01:57,870
and it was positive.
64

64

00:01:57,870  -->  00:02:00,780
The test said it was positive, that means it was positive.
65

65

00:02:00,780  -->  00:02:02,550
And then she actually was pregnant.
66

66

00:02:02,550  -->  00:02:04,110
She had a baby inside of her.
67

67

00:02:04,110  -->  00:02:06,570
So therefore it was a true positive.
68

68

00:02:06,570  -->  00:02:08,250
That's the idea of a true positive.
69

69

00:02:08,250  -->  00:02:10,080
So in terms of cybersecurity,
70

70

00:02:10,080  -->  00:02:12,210
if you have some bad thing on the network
71

71

00:02:12,210  -->  00:02:15,060
and your sensor detected that bad thing and reported on it,
72

72

00:02:15,060  -->  00:02:16,290
that's a true positive.
73

73

00:02:16,290  -->  00:02:17,700
That's what we want to see.
74

74

00:02:17,700  -->  00:02:20,040
We want our tools to be giving us true positives.
75

75

00:02:20,040  -->  00:02:21,390
Those are the most helpful for us
76

76

00:02:21,390  -->  00:02:23,250
because we know there's a bad thing,
77

77

00:02:23,250  -->  00:02:25,530
and we now know it really exists.
78

78

00:02:25,530  -->  00:02:28,080
Now, the next one we have is what's called a false positive.
79

79

00:02:28,080  -->  00:02:30,390
This is when an alert matches a vulnerability
80

80

00:02:30,390  -->  00:02:31,380
and reports on it,
81

81

00:02:31,380  -->  00:02:32,940
but when you look at that system,
82

82

00:02:32,940  -->  00:02:35,040
the vulnerability doesn't exist.
83

83

00:02:35,040  -->  00:02:37,500
So going back to my pregnancy example,
84

84

00:02:37,500  -->  00:02:38,880
my wife thought it would be really funny
85

85

00:02:38,880  -->  00:02:40,680
when she was taking the pregnancy test
86

86

00:02:40,680  -->  00:02:42,330
to have me take one, too.
87

87

00:02:42,330  -->  00:02:44,970
And so she had me do the little urine test,
88

88

00:02:44,970  -->  00:02:47,400
and of course it came back negative, right?
89

89

00:02:47,400  -->  00:02:49,290
Well, if it showed up positive,
90

90

00:02:49,290  -->  00:02:51,090
then that would mean it was a false positive.
91

91

00:02:51,090  -->  00:02:52,590
Because I'm a guy,
92

92

00:02:52,590  -->  00:02:54,600
there's no way that I can be pregnant, right?
93

93

00:02:54,600  -->  00:02:56,280
I am just not going to have that capability
94

94

00:02:56,280  -->  00:02:58,350
because I don't have the body parts to do that.
95

95

00:02:58,350  -->  00:02:59,820
And so that would be a false positive
96

96

00:02:59,820  -->  00:03:02,070
if I had a test that showed positive,
97

97

00:03:02,070  -->  00:03:04,020
but it was my test because I'm a guy.
98

98

00:03:04,020  -->  00:03:05,670
So going back to our computers,
99

99

00:03:05,670  -->  00:03:06,900
if we're thinking about something,
100

100

00:03:06,900  -->  00:03:07,950
I scan a computer,
101

101

00:03:07,950  -->  00:03:08,783
and it says,
102

102

00:03:08,783  -->  00:03:11,640
"You have a Windows vulnerability on this system."
103

103

00:03:11,640  -->  00:03:12,870
And I look at that system,
104

104

00:03:12,870  -->  00:03:15,180
and it's a Linux or a Macintosh system.
105

105

00:03:15,180  -->  00:03:18,750
Well, those systems aren't running Windows operating system.
106

106

00:03:18,750  -->  00:03:20,940
So therefore I can't have a Windows vulnerability
107

107

00:03:20,940  -->  00:03:22,290
on a Mac system.
108

108

00:03:22,290  -->  00:03:23,940
So that would be a false positive.
109

109

00:03:23,940  -->  00:03:25,597
We can mark that off in our system and say,
110

110

00:03:25,597  -->  00:03:26,430
"Ignore that.
111

111

00:03:26,430  -->  00:03:28,800
We understand it's not really real."
112

112

00:03:28,800  -->  00:03:30,720
That's the idea of a false positive.
113

113

00:03:30,720  -->  00:03:32,130
Now, when you're dealing with false positives,
114

114

00:03:32,130  -->  00:03:34,710
the problem with them is that they are very time-consuming
115

115

00:03:34,710  -->  00:03:36,630
because I now have to go investigate them
116

116

00:03:36,630  -->  00:03:38,580
and I start wasting a lot of resources.
117

117

00:03:38,580  -->  00:03:40,110
So if I had 50 things pop up
118

118

00:03:40,110  -->  00:03:41,610
that told me there was Windows vulnerabilities
119

119

00:03:41,610  -->  00:03:42,720
across my network,
120

120

00:03:42,720  -->  00:03:44,400
and I start going and looking at each of those machines
121

121

00:03:44,400  -->  00:03:46,950
and then I find out there's no Windows on that machine,
122

122

00:03:46,950  -->  00:03:47,940
that's a false positive
123

123

00:03:47,940  -->  00:03:50,760
and I wasted time looking at each of those 50 things.
124

124

00:03:50,760  -->  00:03:51,593
Now, what can you do
125

125

00:03:51,593  -->  00:03:53,550
if you start getting a lot of false positives?
126

126

00:03:53,550  -->  00:03:54,690
Well, one of the things you can do is
127

127

00:03:54,690  -->  00:03:56,190
you can start adjusting your scans
128

128

00:03:56,190  -->  00:03:57,960
to a more appropriate scope.
129

129

00:03:57,960  -->  00:04:01,050
Maybe I'm going to have one scope of all my Windows machines,
130

130

00:04:01,050  -->  00:04:03,000
and another scope for all my Linux machines,
131

131

00:04:03,000  -->  00:04:05,340
and another scope for all my Mac machines.
132

132

00:04:05,340  -->  00:04:07,920
That way I can quickly identify false positives
133

133

00:04:07,920  -->  00:04:09,090
based on operating system
134

134

00:04:09,090  -->  00:04:11,460
because of the use cases of those areas.
135

135

00:04:11,460  -->  00:04:13,440
Another thing you can do is create a new baseline
136

136

00:04:13,440  -->  00:04:14,790
for a heuristic scan.
137

137

00:04:14,790  -->  00:04:16,530
If you're using a heuristic scanning engine,
138

138

00:04:16,530  -->  00:04:19,050
a lot of those will generate more false positives.
139

139

00:04:19,050  -->  00:04:21,420
Signature-based tends to be a little bit more accurate.
140

140

00:04:21,420  -->  00:04:23,610
So if you're getting a lot of false positive
141

141

00:04:23,610  -->  00:04:24,870
and you're using heuristics,
142

142

00:04:24,870  -->  00:04:26,430
go ahead and create a new baseline
143

143

00:04:26,430  -->  00:04:28,920
because obviously your baseline is so out of date
144

144

00:04:28,920  -->  00:04:30,090
from what you're currently doing,
145

145

00:04:30,090  -->  00:04:32,220
it's creating a lot of false positives for you.
146

146

00:04:32,220  -->  00:04:33,480
Another thing you might want to do is
147

147

00:04:33,480  -->  00:04:36,030
add the application to an exception list.
148

148

00:04:36,030  -->  00:04:38,310
For instance, if there's a particular application
149

149

00:04:38,310  -->  00:04:40,410
on my system that is throwing up that report
150

150

00:04:40,410  -->  00:04:41,940
and giving me that flag,
151

151

00:04:41,940  -->  00:04:42,773
I might say,
152

152

00:04:42,773  -->  00:04:44,610
"Hey, I understand I'm running Microsoft Word
153

153

00:04:44,610  -->  00:04:46,320
on this particular Mac machine,
154

154

00:04:46,320  -->  00:04:48,510
but it doesn't mean I'm running Word for Windows."
155

155

00:04:48,510  -->  00:04:50,130
So I can put an exception in there
156

156

00:04:50,130  -->  00:04:52,860
to ignore that report every time it comes up.
157

157

00:04:52,860  -->  00:04:54,240
Another thing you might find is
158

158

00:04:54,240  -->  00:04:57,000
that the vulnerability really does exist on that system,
159

159

00:04:57,000  -->  00:04:59,940
but that vulnerability isn't really exploitable.
160

160

00:04:59,940  -->  00:05:01,350
Now what do I mean by this?
161

161

00:05:01,350  -->  00:05:03,750
Maybe I really do have Windows on that system
162

162

00:05:03,750  -->  00:05:05,520
because I'm running a virtual machine,
163

163

00:05:05,520  -->  00:05:06,990
but there's a firewall in place
164

164

00:05:06,990  -->  00:05:09,210
that no inbound or outbound connections can get to it.
165

165

00:05:09,210  -->  00:05:10,950
So therefore it's protected,
166

166

00:05:10,950  -->  00:05:14,250
and therefore we can say that thing is not exploitable,
167

167

00:05:14,250  -->  00:05:15,510
and we can move on.
168

168

00:05:15,510  -->  00:05:18,210
That's just a silly example, but you get the idea here.
169

169

00:05:18,210  -->  00:05:19,560
Now, when you're dealing with this
170

170

00:05:19,560  -->  00:05:21,210
and you start dealing with exceptions
171

171

00:05:21,210  -->  00:05:22,680
because you have a vulnerability that exists
172

172

00:05:22,680  -->  00:05:23,610
but isn't exploitable
173

173

00:05:23,610  -->  00:05:25,950
or an application that you want to do exceptions on,
174

174

00:05:25,950  -->  00:05:28,650
this falls under the idea of exception management.
175

175

00:05:28,650  -->  00:05:31,260
Now, exception management is a defined process
176

176

00:05:31,260  -->  00:05:32,580
to closely monitor systems
177

177

00:05:32,580  -->  00:05:34,650
that cannot be patched or remediated
178

178

00:05:34,650  -->  00:05:37,140
and must be exempted from those scans.
179

179

00:05:37,140  -->  00:05:38,970
Now, the reason we have exception management is
180

180

00:05:38,970  -->  00:05:40,620
because otherwise you would be buried
181

181

00:05:40,620  -->  00:05:42,930
in these false positives all of the time.
182

182

00:05:42,930  -->  00:05:45,390
There are things that would require a valid exception,
183

183

00:05:45,390  -->  00:05:48,900
but, again, a thinking analyst needs to go through them,
184

184

00:05:48,900  -->  00:05:50,670
figure out if they should be an exception,
185

185

00:05:50,670  -->  00:05:51,930
and then follow the process
186

186

00:05:51,930  -->  00:05:54,660
to get them added to that exception list.
187

187

00:05:54,660  -->  00:05:56,010
The next category we have is
188

188

00:05:56,010  -->  00:05:57,960
what's known as a true negative.
189

189

00:05:57,960  -->  00:06:00,330
This occurs when an alert is not generated
190

190

00:06:00,330  -->  00:06:03,540
because there is no matching vulnerability on that system.
191

191

00:06:03,540  -->  00:06:05,850
So going back to my pregnancy example,
192

192

00:06:05,850  -->  00:06:07,200
I am a man.
193

193

00:06:07,200  -->  00:06:10,260
If I take one of those tests, I expect it to be negative.
194

194

00:06:10,260  -->  00:06:13,410
If the test comes back negative, that is a true negative.
195

195

00:06:13,410  -->  00:06:16,620
I have a negative result and I am truly not pregnant
196

196

00:06:16,620  -->  00:06:18,810
because I'm a man and I'm not pregnant.
197

197

00:06:18,810  -->  00:06:20,340
Same thing on cybersecurity.
198

198

00:06:20,340  -->  00:06:23,010
For instance, if I scan Windows vulnerabilities
199

199

00:06:23,010  -->  00:06:24,750
against my Mac system,
200

200

00:06:24,750  -->  00:06:26,790
I expect those results to come back negative.
201

201

00:06:26,790  -->  00:06:28,890
There should be nothing found in that report
202

202

00:06:28,890  -->  00:06:30,780
because if I'm scanning a Mac system
203

203

00:06:30,780  -->  00:06:32,010
for Windows vulnerabilities,
204

204

00:06:32,010  -->  00:06:33,510
I should find nothing
205

205

00:06:33,510  -->  00:06:35,610
because there is no Windows environment there
206

206

00:06:35,610  -->  00:06:36,690
for it to scan.
207

207

00:06:36,690  -->  00:06:38,160
That would be a true negative.
208

208

00:06:38,160  -->  00:06:39,600
That's a good thing.
209

209

00:06:39,600  -->  00:06:40,860
Now, the other side of this is
210

210

00:06:40,860  -->  00:06:42,570
what we call a false negative.
211

211

00:06:42,570  -->  00:06:44,700
This is something that's actually really scary for us
212

212

00:06:44,700  -->  00:06:45,723
in the cybersecurity world.
213

213

00:06:45,723  -->  00:06:47,370
When we talk about a false negative,
214

214

00:06:47,370  -->  00:06:49,410
this is an alert that is not generated
215

215

00:06:49,410  -->  00:06:52,740
even though there's a matching vulnerability on the system.
216

216

00:06:52,740  -->  00:06:55,470
So if I go back to my pregnancy example,
217

217

00:06:55,470  -->  00:06:57,180
this would be a really sad case.
218

218

00:06:57,180  -->  00:06:59,250
There's a couple who's been trying to have a baby.
219

219

00:06:59,250  -->  00:07:01,890
They take a pregnancy test and it comes back negative.
220

220

00:07:01,890  -->  00:07:02,723
And they're really sad
221

221

00:07:02,723  -->  00:07:03,870
because they think they're not pregnant.
222

222

00:07:03,870  -->  00:07:05,940
And they've been trying for months and months.
223

223

00:07:05,940  -->  00:07:07,350
Couple more weeks go by,
224

224

00:07:07,350  -->  00:07:10,110
and then we find out that the woman actually is pregnant.
225

225

00:07:10,110  -->  00:07:11,790
Well, she actually was pregnant the whole time,
226

226

00:07:11,790  -->  00:07:13,620
but the test didn't generate a result for it
227

227

00:07:13,620  -->  00:07:15,180
because it didn't detect it.
228

228

00:07:15,180  -->  00:07:17,460
That's what we're talking about here with a false negative.
229

229

00:07:17,460  -->  00:07:18,750
She got a negative result,
230

230

00:07:18,750  -->  00:07:21,090
but she was actually pregnant the whole time.
231

231

00:07:21,090  -->  00:07:22,590
That is a false negative.
232

232

00:07:22,590  -->  00:07:25,080
Now, when we talk about this in the cybersecurity world,
233

233

00:07:25,080  -->  00:07:26,640
we talk about false negatives,
234

234

00:07:26,640  -->  00:07:28,650
meaning that there is a potential vulnerability
235

235

00:07:28,650  -->  00:07:29,520
in that system
236

236

00:07:29,520  -->  00:07:32,250
or there's a missing patch that hasn't been installed
237

237

00:07:32,250  -->  00:07:34,950
and it's not being identified during scanning.
238

238

00:07:34,950  -->  00:07:37,170
That's what makes these so dangerous.
239

239

00:07:37,170  -->  00:07:39,660
The problem here is you don't know you're vulnerable
240

240

00:07:39,660  -->  00:07:42,060
because your report says you're not vulnerable,
241

241

00:07:42,060  -->  00:07:43,170
but yet there's vulnerabilities
242

242

00:07:43,170  -->  00:07:44,790
that really do exist on the system.
243

243

00:07:44,790  -->  00:07:47,520
So this is actually probably the worst of these four cases.
244

244

00:07:47,520  -->  00:07:48,480
So something to keep in mind
245

245

00:07:48,480  -->  00:07:49,620
as you're going through and working
246

246

00:07:49,620  -->  00:07:51,420
as a cybersecurity analyst.
247

247

00:07:51,420  -->  00:07:53,160
Now, what can you do to mitigate the threat
248

248

00:07:53,160  -->  00:07:55,140
of these false negatives?
249

249

00:07:55,140  -->  00:07:57,960
Well, one of the things you can do is run repeated scans.
250

250

00:07:57,960  -->  00:07:59,640
Maybe your scanner was having a bad day
251

251

00:07:59,640  -->  00:08:00,870
and it just didn't catch it.
252

252

00:08:00,870  -->  00:08:02,640
So maybe you want to run another scan
253

253

00:08:02,640  -->  00:08:04,500
and it catches it the second time.
254

254

00:08:04,500  -->  00:08:06,570
Or you might use different scan types,
255

255

00:08:06,570  -->  00:08:08,130
or even a different scanner.
256

256

00:08:08,130  -->  00:08:09,990
So maybe I tried scanning it with Nessus
257

257

00:08:09,990  -->  00:08:10,830
and it didn't pick it up,
258

258

00:08:10,830  -->  00:08:12,300
but now I'm going to scan it with Qualys,
259

259

00:08:12,300  -->  00:08:13,590
and that one did pick it up,
260

260

00:08:13,590  -->  00:08:15,180
or something of that nature.
261

261

00:08:15,180  -->  00:08:16,800
Another thing you might want to do is
262

262

00:08:16,800  -->  00:08:18,510
use different sensitivities.
263

263

00:08:18,510  -->  00:08:20,670
Maybe you are running it in safe mode.
264

264

00:08:20,670  -->  00:08:22,530
Now you're going to run it in not safe mode,
265

265

00:08:22,530  -->  00:08:24,690
which will allow you to do more exploitation there
266

266

00:08:24,690  -->  00:08:26,250
and find additional vulnerabilities
267

267

00:08:26,250  -->  00:08:28,230
that weren't found the first time.
268

268

00:08:28,230  -->  00:08:30,060
Another thing you can do is use a different scanner,
269

269

00:08:30,060  -->  00:08:30,893
like I said.
270

270

00:08:30,893  -->  00:08:33,810
We switch from Nessus to Openvas, or Openvas to Qualys,
271

271

00:08:33,810  -->  00:08:34,950
or Qualys to Nikto,
272

272

00:08:34,950  -->  00:08:36,450
or whatever we want to do.
273

273

00:08:36,450  -->  00:08:37,500
We can use a different scanner
274

274

00:08:37,500  -->  00:08:39,540
and that might give us a better result.
275

275

00:08:39,540  -->  00:08:41,160
Now, we've done all of our scanning.
276

276

00:08:41,160  -->  00:08:44,130
We understand our four types of classifications.
277

277

00:08:44,130  -->  00:08:46,830
Let's start validating our scan reports.
278

278

00:08:46,830  -->  00:08:49,410
When you run a scan, you're going to get a scan report,
279

279

00:08:49,410  -->  00:08:51,060
and they look something like this.
280

280

00:08:51,060  -->  00:08:54,120
They'll give you a nice report with an executive summary,
281

281

00:08:54,120  -->  00:08:55,620
different vulnerabilities by host,
282

282

00:08:55,620  -->  00:08:58,140
and then details on each of those vulnerabilities
283

283

00:08:58,140  -->  00:09:00,870
so you can look at them and then validate them.
284

284

00:09:00,870  -->  00:09:04,020
So once we have our report, we have to validate that report.
285

285

00:09:04,020  -->  00:09:06,390
And there are four things we're going to do to validate it.
286

286

00:09:06,390  -->  00:09:08,670
First, we're going to reconcile the results.
287

287

00:09:08,670  -->  00:09:11,730
Second, we're going to correlate results with other sources.
288

288

00:09:11,730  -->  00:09:14,040
Third, we're going to compare them to best practices.
289

289

00:09:14,040  -->  00:09:16,710
And fourth, we're going to identify exceptions.
290

290

00:09:16,710  -->  00:09:18,990
So first, we want to reconcile these results
291

291

00:09:18,990  -->  00:09:21,600
because the scanners can misinterpret the information
292

292

00:09:21,600  -->  00:09:23,460
that they're receiving from their probes.
293

293

00:09:23,460  -->  00:09:24,780
Again, this is the idea
294

294

00:09:24,780  -->  00:09:27,570
of making sure we identify things as truly positive,
295

295

00:09:27,570  -->  00:09:30,990
false positives, truly negative, or false negatives,
296

296

00:09:30,990  -->  00:09:32,400
and being able to categorize these things
297

297

00:09:32,400  -->  00:09:33,780
as we reconcile those results.
298

298

00:09:33,780  -->  00:09:37,200
That is a big part of a cybersecurity analyst job.
299

299

00:09:37,200  -->  00:09:39,420
Second, we want to correlate the scan results
300

300

00:09:39,420  -->  00:09:40,950
with other data sources.
301

301

00:09:40,950  -->  00:09:44,220
And we do this by reviewing related system and network logs.
302

302

00:09:44,220  -->  00:09:46,357
So if I went and did a scan that says,
303

303

00:09:46,357  -->  00:09:47,610
"Hey, you have a vulnerability.
304

304

00:09:47,610  -->  00:09:50,040
Port 80 is open on this workstation,"
305

305

00:09:50,040  -->  00:09:51,600
I'm going to going to go look at that workstation
306

306

00:09:51,600  -->  00:09:53,460
and verify if port 80 is open.
307

307

00:09:53,460  -->  00:09:55,710
And if it is open, is it supposed to be open,
308

308

00:09:55,710  -->  00:09:57,750
because maybe they are running a web server there
309

309

00:09:57,750  -->  00:09:59,280
and they were allowed to do that.
310

310

00:09:59,280  -->  00:10:00,113
If they were,
311

311

00:10:00,113  -->  00:10:02,850
then that might be something we want to add an exception to.
312

312

00:10:02,850  -->  00:10:04,200
Now, the third thing we want to do is
313

313

00:10:04,200  -->  00:10:06,480
compare the results to best practices.
314

314

00:10:06,480  -->  00:10:08,700
This allows to determine if there's a high priority
315

315

00:10:08,700  -->  00:10:11,670
or a low risk associated with this particular finding.
316

316

00:10:11,670  -->  00:10:12,750
Sometimes the findings
317

317

00:10:12,750  -->  00:10:14,550
in your report are going to be informational.
318

318

00:10:14,550  -->  00:10:15,607
It might say something like,
319

319

00:10:15,607  -->  00:10:16,680
"The best practice is
320

320

00:10:16,680  -->  00:10:18,690
not to run web servers from a workstation.
321

321

00:10:18,690  -->  00:10:21,060
You should only do this from a server-based environment
322

322

00:10:21,060  -->  00:10:23,430
like Windows Server 2019."
323

323

00:10:23,430  -->  00:10:24,420
If that's the case,
324

324

00:10:24,420  -->  00:10:25,627
you're going to have to look at that and say,
325

325

00:10:25,627  -->  00:10:27,270
"Yeah, I understand that,
326

326

00:10:27,270  -->  00:10:29,460
but my organization wants to run this web server
327

327

00:10:29,460  -->  00:10:31,290
on Windows 10."
328

328

00:10:31,290  -->  00:10:32,310
And if that's what they want to do
329

329

00:10:32,310  -->  00:10:33,570
and they've accepted the risk,
330

330

00:10:33,570  -->  00:10:35,100
then that's an acceptable thing to do.
331

331

00:10:35,100  -->  00:10:36,387
Just make sure you note it.
332

332

00:10:36,387  -->  00:10:38,310
And that brings us to our fourth category,
333

333

00:10:38,310  -->  00:10:40,380
which is identifying exceptions.
334

334

00:10:40,380  -->  00:10:42,360
Any findings whose risk has been accepted
335

335

00:10:42,360  -->  00:10:45,000
or transferred by the organization can be added
336

336

00:10:45,000  -->  00:10:46,110
to your exception list.
337

337

00:10:46,110  -->  00:10:48,930
This way, those same things don't show up week after week
338

338

00:10:48,930  -->  00:10:50,400
and month after month.
339

339

00:10:50,400  -->  00:10:52,650
This will allow your reports to be smaller in size,
340

340

00:10:52,650  -->  00:10:54,330
quicker to reconcile in the future,
341

341

00:10:54,330  -->  00:10:56,610
and you're not bringing up the same issues to management
342

342

00:10:56,610  -->  00:10:57,720
over and over again
343

343

00:10:57,720  -->  00:10:59,670
that they've already made decisions on.
