What's changed: Initial version
4.1Vulnerability management
Covers vulnerability management, the continuous cycle of finding and fixing weaknesses (identify -> manage -> mitigate); the difference between active reconnaissance (touching the target directly) and passive reconnaissance (using only public information and observation); and port scanning to list open ports plus automation for repetitive work—as the foundation for working out "where the holes are and how to close them."
The first step in protecting a system is knowing "where the weak spots are." Finding and closing the holes yourself before an attacker finds them first—this continuous effort is vulnerability management. This section covers the flow of finding weaknesses (identify), organizing and prioritizing them (manage), and closing them with patches or configuration changes (mitigate); the difference in how you investigate—active reconnaissance vs. passive reconnaissance; and the representative technique of port scanning plus the automation that streamlines repetitive work—learned not by rote but through the lens of "which hole to close, and how."
4.1.1The vulnerability management cycle
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

