A vulnerability scan is scheduled across an IaaS subnet that contains a legacy host known to lock up when contacted by active checks. The system cannot be patched soon, but the SOC still needs visibility into its risk. Which scanning approach should be used to protect the host while maintaining coverage?
Select an answer to reveal the explanation.
Short Explanation
Think of a fragile legacy system like an old pump: if you crank the pressure too high, it seizes up. You exclude it from active scanning and watch it with passive telemetry instead. That keeps the scan from causing downtime while still giving you a safety net.
Full Explanation
Active scanning sends probes, credentialed queries, or service checks that can consume limited resources on legacy systems. When a host is known to lock up under active checks, the appropriate method is a scoped exclusion from that scan plus compensating monitoring, such as passive traffic analysis, log review, or file-integrity checks. This preserves scan coverage elsewhere while avoiding an availability incident. A maintenance window reduces scan impact but does not remove the possibility that credentialed or active checks will still destabilize the system. Reducing scanner concurrency globally can slow the scan and may still touch the fragile host, while affecting many unrelated systems unnecessarily. Converting from credentialed to uncredentialed scanning can still send probes and generally reduces reliability, so it does not address the stability concern. Exam caveat: exclusions must be risk-accepted, documented, narrowly scoped, and periodically reviewed. Operational check: confirm the exclusion applies only to the fragile host and that passive telemetry or log alerts are enabled for it.