Download as pdf or txt
Download as pdf or txt
You are on page 1of 115

Tenable University

Tenable.sc Specialist
Course

Slide Decks









• •

• •
• •
• • •
• • • • •
• • • • •
• • •
• • •
• • •

• • •
• • • • •
• • • • • •
• • • • •



• •
• •
• •
• •


For more information, visit us at:


tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721
For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721
Core
Core

VM VM VM
.DER, .PEM, .CRT

PORT
443

For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721
For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721





For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721



For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721
ACT_DESTRUCTIVE_ATTACK
ACT_DENIAL
ACT_KILL_HOST
ACT_FLOOD
For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721


<custom_item>
type : AUDIT_POWERSHELL
description : "Test the Lockout Threshold"
value_type : POLICY_TEXT
value_data : "[Ll]ockout threshold:[\s]*[1-9][\d]*"
powershell_args : "net accounts | findstr /c:'Lockout threshold'"
check_type : CHECK_REGEX
</custom_item>
# This is an Audit file to check for minimum password length of 15 characters

<check_type:"Windows" version:"2">

<group_policy:"Password Length">

<custom_item>

type: PASSWORD_POLICY

description: "Minimum password length"

info : “Minimum password length should be 15 characters”

value_type: POLICY_DWORD

value_data: 15

password_policy: MINIMUM_PASSWORD_LENGTH

</custom_item>

</group_policy>

</check_type>
IF THEN

<if>

<condition type:"AND">

<custom_item>

type : REGISTRY_SETTING

description : "Windows Server 2019 is installed"

value_type : POLICY_TEXT

value_data : "^[a-zA-Z0-9\(\)\s]*2019[\s]*[a-zA-Z0-9\(\)\s]*$"

reg_key : "HKLM\Software\Microsoft\Windows Nt\Currentversion"

reg_item : "ProductName"

check_type : CHECK_REGEX

</custom_item>

</condition>

<then>
<report type:"PASSED">
description : "CIS_DC_SERVER_2019_Level_2_v1.1.0.audit
from CIS Microsoft Windows Server 2019 Benchmark"
see_also : "https://workbench.cisecurity.org/files/2630"
</report>
For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721



For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721












IP
CSV RTF PDF

CSV

RTF PDF
Filter
Aa IP, Vulnerability, or Port 1

Aa IP, Vulnerability, or Port 2

Aa IP, Vulnerability, or Port 3

Aa IP, Vulnerability, or Port 4

Aa Aa IP, Vulnerability, or Port 5


Aa
Aa
Aa IP, Vulnerability, or Port 6

Aa IP, Vulnerability, or Port 7

Aa IP, Vulnerability, or Port 8

Aa IP, Vulnerability, or Port 9


Logo

Watermark

Footer
For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721
Goals and objectives

Business Critical success


factors
KPIs
Report cards
provide KPI on
security posture
Metrics
Technology
Measures

All hosts Asset list

IP/DNS
Repository
range
For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721


For more information, visit us at:
tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 010721





For more information, visit us at:


tenable.com/education
COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO, TENABLE NETWORK SECURITY, NESSUS,
SECURITYCENTER, SECURITYCENTER CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER EXPOSURE COMPANY ARE
TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

rev 012921
Tenable University

About

About Tenable
Tenable®, Inc. is the Cyber Exposure company. Over 30,000 organizations around
the globe rely on Tenable to understand and reduce cyber risk. As the creator of
Nessus®, Tenable extended its expertise in vulnerabilities to deliver the world’s
first platform to see and secure any digital asset on any computing platform.
Tenable customers include more than 50 percent of the Fortune 500, more than 30
percent of the Global 2000 and large government agencies. Learn more at
www.tenable.com.

For more information about Tenable Customer Education, visit us at:


tenable.com/education

COPYRIGHT 2021 TENABLE, INC. ALL RIGHTS RESERVED. TENABLE, TENABLE.IO,


TENABLE NETWORK SECURITY, NESSUS, SECURITYCENTER, SECURITYCENTER
CONTINUOUS VIEW AND LOG CORRELATION ENGINE ARE REGISTERED TRADEMARKS
OF TENABLE, INC. TENABLE.SC, TENABLE.OT, LUMIN, INDEGY, ASSURE, AND THE CYBER
EXPOSURE COMPANY ARE TRADEMARKS OF TENABLE, INC. ALL OTHER PRODUCTS OR
SERVICES ARE TRADEMARKS OF THEIR RESPECTIVE OWNERS.

Rev 010721

You might also like