Assignment No.
02 Total Marks: 10
Semester: Fall 2024
CS205: Information Security Due Date: January 17, 2024
Instructions:
Please read the following instructions carefully before submitting assignment:
You need to use MS Word document to prepare and submit the assignment on VU-LMS.
It should be clear that your assignment will not get any credit if:
The assignment is submitted after due date.
The assignment is not in the required format (doc or docx).
The submitted assignment does not open or file is corrupt.
Assignment is copied (partial or full) from any source (websites, forums, students, etc.).
Objectives:
To enhance the learning capabilities of the students about:
Vulnerability Management and its Tools
Assignment
Question No.1
You are required to download the trial version of Nessus tool and install on your PC/Laptop. You may visit the
following link for downloading this tool:
Nessus compliance scan for “DISA STIG:
Following are the steps as under:
Create the "Nessus Local Access" Security Group:
1. Log in to a Domain Controller and open Active Directory Users and Computers.
2. To create a security group, select Action > New > Group.
3. Name the group Nessus Local Access. Set Scope to Global and Type to Security.
4. Add the account you plan to use to perform Tenable Nessus Windows Authenticated Scans to the
Tenable Nessus Local Access group.
Create the "Nessus Scan GPO" Group Policy:
1. Open the Group Policy Management Console.
2. Right-click Group Policy Objects and select New.
3. Type the name of the policy Nessus Scan GPO.
4. Add the "Nessus Local Access" Group to the "Nessus Scan GPO" Policy
5. Right-click Nessus Scan GPO Policy, then select Edit.
6. Expand Computer configuration > Policies > Windows Settings > Security Settings > Restricted Groups.
7. In the left navigation bar on Restricted Groups, right-click and select Add Group.
8. In the Add Group dialog box, select browse and enter Nessus Local Access.
9. Select Check Names.
10. Select OK twice to close the dialog box.
11. Select Add under This group is a member of:
12. Add the Administrators Group.
13. Select OK twice.
Tenable Nessus uses Server Message Block (SMB) and Windows Management Instrumentation (WMI). Ensure
Windows Firewall allows access to the system.
1. Allow WMI on Windows
2. Right-click Nessus Scan GPO Policy, then select Edit.
3. Expand Computer Configuration> Policies > Windows Settings > Security Settings > Windows Firewall
with Advanced Security > Windows Firewall with Advanced Security > Inbound Rules.
4. Right-click in the working area and choose New Rule....
5. Choose the Predefined option, and select Windows Management Instrumentation (WMI) from the drop-
down box.
6. Select Next.
7. Select the checkboxes for:
8. Windows Management Instrumentation (ASync-In)
9. Windows Management Instrumentation (WMI-In)
10. Windows Management Instrumentation (DCOM-In)
11. Select Next.
12. Select Finish.