Option Description
Do not perform application fingerprinting Does not try to specifically identify which
applications are communicating over which
ports, and runs the checks as selected in the
Assessment policy.
This option does not identify applications
communicating over non-standard ports.
(Checks are run against standard ports as
defined in the Network Services policy.)
Fingerprint applications and run checks
that apply to application protocol (e.g.,
http)
Identifies applications communicating over
specific ports, and then runs checks that
apply to the protocol in use.
This option identifies applications
communicating over non-standard ports.
Fingerprint applications and run checks
that apply to specific application (e.g.,
apache)
Identifies applications communicating over
specific ports, and then runs checks that
apply only to the application identified.
This option identifies applications
communicating over non-standard ports.
10. The settings in the Account Verification section apply only if anAssessmentCredentials policy is available for the group being scanned.
Option Description
Verifyaccount access level before using vIf disabled, Enterprise Scanner assumes
that whatever is specified in the
Assessment Credentials policy is accurate.
vIf enabled, Enterprise Scanner tries to
confirm that the access level specified in
the Assessment Credentials policy is
correct.
Important: You should enable the Check
local group membership to verify access
level if you enable account verification.
Access domain controllers to verify access
level
vIf disabled, Enterprise Scanner does not
communicate with a Domain Controller in
the process of verifying access levels.
vIf enabled, Enterprise Scanner tries to
communicate with a Domain Controller in
the process of verifying access levels.
Check local group membership to verify
access level
vIf disabled, Enterprise Scanner does not
try to confirm the access level of the
account during assessment by checking
which local groups the asset belong to.
vIf enabled, Enterprise Scanner tries to
confirm the access level of the account
during assessment by checking which
local groups the asset belong to.
11. Configure the options for locking out accounts in the Account LockoutControl section:
Chapter3. Enterprise Scanner policies 53