VM Scanner Background Report CMIT 421 Threat Management and Vulnerability Assessment Introduction Provide an introduction that includes what you intend to cover in the background
paper. Ensure you are specific and define your purpose clearly. Part 1: Nessus Vulnerability Report Analysis In this section, analyze and interpret the results of the report to give your boss a clear picture of the Mercury USA's potential vulnerabilities. As you analyze the report, address the following points: • • • . Is it appropriate to distribute the report as is, or do you need to interpret the report, attach meaning before sending to management? Explain why or why not. What is your overall impression of the tool's output? Is it easy to interpret, well- organized, include enough detail, too much detail? Does the tool provide enough reporting detail for you as the analyst to focus on the relevant vulnerabilities for Mercury USA? Name the three most important vulnerabilities in this system for Mercury USA. Why are they the most critical? How does the report provide enough information to address and remediate the three most important vulnerabilities? Take Note: Judy has asked you to provide a screenshot to help her understand what the Nessus report looks like. Screenshot Instructions Open Lab 4.5.x, "Conducting Vulnerability Scans" within the uCertify Pearson CompTIA Cybersecurity Analyst (CySA+) content • After Step 25, click on the scan "General Scan" • Click the Report button dropdown and choose HTML • In the "Generate HTML Report" dialog, click the Generate Report button Open the report from the browser's download bar at the bottom of the screen Click the Show Details button Take a full window screenshot that includes the date/time of the report and the date/time area of the VM's taskbar (refer to the example below) OPEN uCertify ## 027858-01-2212-OL2-6981 [Based on CompTIA Cybersecurity Analyst (CYSA+)] Nessus Essentials / Folders/View X General Scan SEND TEXT CTRL+ALT+DEL File file:///C:/Users/Administrator/Downloads/General_Scan_90rse1.html nessus General Scan Wed, 10 Feb 2021 11:42:22 Pacific Standard Time TABLE OF CONTENTS Hosts Executive Summary .10.51.182.124 RIGHT CLICK ntials Hosts Executive Summary 10.51.182.124 Ensure the two highlighted areas are clearly visible in your screenshot Report generated by Nessus™ Collapse All Expand All 12 49 17 2 118 CRITICAL HIGH Severity CVSS Plugin Name CRITICAL 10.0 100760 CRITICAL 10.0 101366 MEDIUM LOW KB4022715: Windows 10 Version 1607 and Windows Server 216 June 2017 Cumulative Update KB4025339: Windows 10 Version 1607 and Windows Server 2016 Ju 2017 Cumulative Update INFO CRITICAL 10.0 103749 KB4041691: Windows 10 Version 1607 and Windows Server 2016 October 017 Cumulative Update (KRACK) CRITICAL 10.0 117413 KB4457131: Windows 10 Version 1607 and Windows Server 2016 September 20Security Update CRITICAL 10.0 118916 KB4467691: Windows 10 Version 1607 and Windows Server 2016 November 2018 Secty Update CRITICAL 10.0 119584 KB4471321: Windows 10 Version 1607 and Windows Server 2016 December 2018 Security Upate CRITICAL 10.0 127850 KB4512517: Windows 10 Version 1607 and Windows Server 2016 August 2019 Security Update CRITICAL 10.0 132858 KB4534271: Windows 10 Version 1607 and Windows Server 2016 January 2020 Security Update CRITICAL 10.0 134369 KB4540670: Windows 10 Version 1607 and Windows Server 2016 March 2020 Security Update O CRITICAL 10.0 119612 Security Updates for Microsoft .NET Framework (December 2018) CRITICAL 10.0 132999 Security Updates for Microsoft .NET Framework (January 2020) CRITICAL 10.0 117431 Security Updates for Microsoft .NET Framework (September 2018) 12:10 PM 2/10/2021 Note: This portion of the background paper also helps determine that your submission is unique. Thus, you must include the specific screenshot as seen below or your project will not be accepted. Part 2: The Business Case Keep these issues in mind as you address the two questions below: • • Think back to the video from Mercury USA's CEO. What were his main areas of concern? What is the industry/function of the organization? • What kinds of data might be important to the organization? What is your assessment of the Mercury USA's overall current security posture? What information in the vulnerability scans supports your assessment? Based on the vulnerabilities present in the reports and the information available about them, what threats might an adversary or black hat hacker try to use against the organization to exfiltrate data or hold it for ransom? Part 3: Nessus Purchase Recommendation State your case for your recommendation of the Nessus commercial vulnerability scanner. Be sure to address the following questions: • Do you think the overall presentation and scoring features are adequate for technical professionals? • How can this tool help Mercury USA comply with regulatory and standards requirements? • What is the cost to license the tool? Does the usability, support, and efficacy of the tool warrant the cost? • Do you think the Nessus report is understandable/suitable for management? Explain why or why not. • Would you recommend that Mercury USA purchase the tool? Provide your rationale for this recommendation. Conclusion Provide a conclusion of at least a paragraph summarizing your analysis of the Nessus vulnerability report, your purchase recommendation, and why your purchase recommendation is beneficial for employees, management, and the organization. References Use in-text citations in the body of your memorandum as appropriate. Add all sources you used here. This example citation uses IEEE style. Use a style of your choice or ask your instructor for clarification. When using the associated course content, ensure you cite to the chapter level. An example IEEE citation is provided below for your reference. [1] "Chapter 5: Implementing an Information Security Vulnerability Management Process", Pearson CompTIA Cybersecurity Analyst (CYSA+), 2020. [Online]. Available: https://www.ucertify.com/. [Accessed: 28-Apr-2020].