Security Testing: Vulnerability Management with Nessus

Security Testing: Vulnerability Management with Nessus

1h 46mIntermediate2019-10-03

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

It only takes one misconfigured device or missing patch for hackers to infiltrate your network. Fix the flaws in your systems before attackers can find them with Nessus, the network vulnerability scanner popular among cybersecurity analysts, sys admins, and network engineers. Using Nessus, you can scan servers, endpoints, and other network devices and check them against a database of thousands of known vulnerabilities. In this course, instructor Mike Chapple teaches you how to install Nessus, configure scans, and interpret the output. He explains how to create a vulnerability management program as well as a remediation workflow that will help you detect, understand, and resolve vulnerabilities before they are exploited.

Learning objectives
Setting up Nessus on Linux and Windows
Identifying scan targets and frequency
Configuring vulnerability scans
Reporting scan results
Overcoming barriers to vulnerability remediation

Skills covered

NessusTenableVulnerability ManagementCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • Managing vulnerabilities with Nessus
  • What you need to know

Setting Up Nessus

  • Nessus editions
  • Installing Nessus Manager on Linux
  • Installing Nessus Manager on Windows
  • Accessing the Nessus console

Creating a Vulnerability Management Program

  • What is vulnerability management
  • Identify scan targets
  • Scan frequency

Configuring and Executing Vulnerability Scans

  • Scan configuration
  • Scan perspective
  • Scanner maintenance
  • Vulnerability Scanning Tools

Remediating Vulnerabilities

  • Report scan results
  • Prioritize remediation
  • Create a remediation workflow
  • Barriers to vulnerability remediation

Analyzing Scan Results

  • SCAP
  • CVSS
  • Interpreting CVSS scores
  • Analyzing scan reports
  • Correlating scan results

Common Vulnerabilities

  • Server vulnerabilities
  • Endpoint vulnerabilities
  • Network vulnerabilities
  • Virtualization vulnerabilities
  • Industrial control systems
  • Understanding cross-site scripting
  • Preventing SQL injection

Conclusion

  • Next steps
40,000 Toman