{"id":17277,"date":"2020-08-21T05:50:29","date_gmt":"2020-08-21T05:50:29","guid":{"rendered":"https:\/\/www.testpreptraining.com\/tutorial\/?page_id=17277"},"modified":"2022-04-16T04:49:43","modified_gmt":"2022-04-16T04:49:43","slug":"configuring-vulnerability-scanning","status":"publish","type":"page","link":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/","title":{"rendered":"Configuring Vulnerability scanning"},"content":{"rendered":"\n<p><a href=\"https:\/\/www.testpreptraining.ai\/tutorial\/exam-az-500-microsoft-azure-security-technologies\/\" target=\"_blank\" rel=\"noreferrer noopener\">Go back to AZ-500 Tutorials<\/a><\/p>\n\n\n\n<p>In this tutorial, we will learn about configuring vulnerability scanning for virtual machines.<\/p>\n\n\n\n<p>You should be aware that identifying and analyzing vulnerabilities is an important part of any cyber risk and security program. The normal pricing tier of Azure Security Center, on the other hand, includes free vulnerability scanning for your virtual machines. Furthermore, the Security Center can deploy this tool for you automatically.<\/p>\n\n\n\n<p>Security Center presents two recommendations if it doesn\u2019t find a vulnerability assessment solution installed on a VM:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Firstly, <em>enabling the built-in vulnerability assessment solution on virtual machines (powered by Qualys)<\/em>. This recommendation only appears in standard tiers. As this is an invitation for installing an Azure Security Center vulnerability assessment extension (powered by Qualys) for you at no additional cost.&nbsp;<\/li><li>Secondly, <em>Vulnerability assessment solutions should be installed on your virtual machines. <\/em>This is for installing any of the supported partner solutions. However, you\u2019ll need to purchase a license for your chosen solution separately. In turn, that platform provides vulnerability and health monitoring data back to the Security Center. Moreover, you can point out vulnerable VMs on the Security Center dashboard.&nbsp;<\/li><\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Integrating vulnerability scanning for virtual machines<\/strong><\/h4>\n\n\n\n<p>The vulnerability scanner is included with Azure Security Center which is powered by Qualys. Where Qualys&#8217; scanner refers to the leading tool for real-time identification of vulnerabilities in your Azure Virtual Machines.\u00a0<\/p>\n\n\n\n<p>The vulnerability scanner extension works as follows:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Firstly, deploying. In this, the Azure Security Center deploys the Qualys extension for the selective virtual machine\/s.<\/li><li>Secondly, gathering information. In this, the extension collects artifacts and sends them for analysis in the Qualys cloud service in the defined region.<\/li><li>Next, analyzing. In this, the Qualys&#8217; cloud service conducts the vulnerability assessment and sends its findings to the Security Center.<\/li><li>Lastly, reporting. This means the findings are available to you in the Security Center.<\/li><\/ul>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"https:\/\/www.testpreptraining.ai\/microsoft-azure-security-technologies-az-500-free-practice-test\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" width=\"961\" height=\"150\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ_500-practice-tests-11.png\" alt=\"AZ-500 Practice tests\" class=\"wp-image-17972\" srcset=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ_500-practice-tests-11.png 961w, https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ_500-practice-tests-11-750x117.png 750w\" sizes=\"auto, (max-width: 961px) 100vw, 961px\" \/><\/a><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Deploying the Qualys built-in vulnerability scanner<\/strong><\/h4>\n\n\n\n<p>The simplest way for scanning Azure-based virtual machines for vulnerabilities is to use the built-in vulnerability scanner.<\/p>\n\n\n\n<p>For deploying the vulnerability scanner:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Firstly, open Azure Security Center and go to the Recommendations page for a subscription on the standard pricing tier.<\/li><li>Secondly, select the recommendation named &#8220;Enable the built-in vulnerability assessment solution on virtual machines (powered by Qualys)&#8221;<\/li><li>Then, your VMs will appear in one or more of the following groups:<ul><li><strong>Healthy resources<\/strong>: this means the vulnerability scanner extension has been deployed to these VMs.<\/li><li><strong>Unhealthy resources<\/strong>: this means the vulnerability scanner extension can be deployed to these VMs.<\/li><li><strong>Not applicable resources<\/strong>: this states these VMs cannot have the vulnerability scanner extension deployed. That means, your VM might be in this tab. The reason can be it is on the free pricing tier, it is an image in an AKS cluster or it is not running one of the supported OSes:<\/li><\/ul><\/li><\/ul>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/az500-docs-39.png\" alt=\"vulnerability scanner supported OS\" class=\"wp-image-17299\" width=\"628\" height=\"402\" srcset=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/az500-docs-39.png 767w, https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/az500-docs-39-624x400.png 624w\" sizes=\"auto, (max-width: 628px) 100vw, 628px\" \/><figcaption><strong>Image Source: Microsoft<\/strong><\/figcaption><\/figure><\/div>\n\n\n\n<ul class=\"wp-block-list\"><li>Fourthly, from the Unhealthy resources tab, select the VMs on which you want to deploy the Qualys scanner and click Remediate. However, the scanner extension will install on all of the VMs within a few minutes and the scanning begins automatically as soon as the extension is successfully deployed.\u00a0<\/li><li>Lastly, if the deployment fails on one or more VMs, then it ensure the target VMs can communicate with Qualys&#8217; cloud service on the two IP addresses that include:<ul><li>64.39.104.113 &#8211; Qualys&#8217; US data center<\/li><li>154.59.121.74 &#8211; Qualys&#8217; European data center<\/li><\/ul><\/li><\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Viewing and remediating discovered vulnerabilities<\/strong><\/h4>\n\n\n\n<p>When the Security Center identifies vulnerabilities, then it presents findings and related information as recommendations. However, the related information includes remediation steps, related CVEs, CVSS scores, and more.&nbsp;<\/p>\n\n\n\n<p>For viewing the findings and remediate the identified vulnerability:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Firstly, open Azure Security Center and go to the Recommendations page.<\/li><li>Secondly, select the recommendation named &#8220;Remediate vulnerabilities found on your virtual machines (powered by Qualys)&#8221;.<\/li><li>Then, the Security Center shows you all the findings for all VMs in the currently selected subscriptions. The findings are ordered by severity.<\/li><li>Fourthly, for filtering the findings by a specific VM, open the &#8220;Affected resources&#8221; section and click the VM that interests you.\u00a0<\/li><li>After that, for learning more about a specific vulnerability, select it.<\/li><li>However, the details pane that appears contains extensive information about the vulnerability, including:<ul><li>Firstly, links to all relevant CVEs (where available)<\/li><li>Secondly, remediation steps<\/li><li>Thirdly, any additional reference pages<\/li><\/ul><\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Lastly, for remediating a finding, follow the remediation steps from this details pane.<\/li><\/ul>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><a href=\"https:\/\/www.testpreptraining.ai\/microsoft-azure-security-technologies-az-500-practice-exam\" target=\"_blank\" rel=\"noopener noreferrer\"><img decoding=\"async\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ-500-online-course-11.png\" alt=\"AZ-500 Online Course\"\/><\/a><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-right\"><strong>Reference: <\/strong><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/built-in-vulnerability-assessment\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Documentation<\/a>, <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/security-center-vulnerability-assessment-recommendations#implement-a-vulnerability-assessment-recommendation\" target=\"_blank\" rel=\"noreferrer noopener\">Documentation 2<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.testpreptraining.ai\/tutorial\/exam-az-500-microsoft-azure-security-technologies\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><a href=\"https:\/\/www.testpreptraining.ai\/tutorial\/exam-az-500-microsoft-azure-security-technologies\/\" target=\"_blank\" rel=\"noreferrer noopener\">Go back to AZ-500 Tutorials<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Go back to AZ-500 Tutorials In this tutorial, we will learn about configuring vulnerability scanning for virtual machines. You should be aware that identifying and analyzing vulnerabilities is an important part of any cyber risk and security program. The normal pricing tier of Azure Security Center, on the other hand, includes free vulnerability scanning for&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"categories":[],"tags":[],"class_list":["post-17277","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Configuring Vulnerability scanning | Microsoft Azure AZ-500 Tutorials<\/title>\n<meta name=\"description\" content=\"Enhance your skills by learning about configuring Vulnerability scanning using Microsoft AZ-500 online course and Practice Exam Now!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Configuring Vulnerability scanning | Microsoft Azure AZ-500 Tutorials\" \/>\n<meta property=\"og:description\" content=\"Enhance your skills by learning about configuring Vulnerability scanning using Microsoft AZ-500 online course and Practice Exam Now!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/\" \/>\n<meta property=\"og:site_name\" content=\"Testprep Training Tutorials\" \/>\n<meta property=\"article:modified_time\" content=\"2022-04-16T04:49:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ_500-practice-tests-11.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/\",\"name\":\"Configuring Vulnerability scanning | Microsoft Azure AZ-500 Tutorials\",\"isPartOf\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\"},\"datePublished\":\"2020-08-21T05:50:29+00:00\",\"dateModified\":\"2022-04-16T04:49:43+00:00\",\"description\":\"Enhance your skills by learning about configuring Vulnerability scanning using Microsoft AZ-500 online course and Practice Exam Now!\",\"breadcrumb\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Configuring Vulnerability scanning\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#website\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"name\":\"Testprep Training Tutorials\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#organization\",\"name\":\"Testprep Training\",\"url\":\"https:\/\/www.testpreptraining.ai\/tutorial\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"contentUrl\":\"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png\",\"width\":583,\"height\":153,\"caption\":\"Testprep Training\"},\"image\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Configuring Vulnerability scanning | Microsoft Azure AZ-500 Tutorials","description":"Enhance your skills by learning about configuring Vulnerability scanning using Microsoft AZ-500 online course and Practice Exam Now!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/","og_locale":"en_US","og_type":"article","og_title":"Configuring Vulnerability scanning | Microsoft Azure AZ-500 Tutorials","og_description":"Enhance your skills by learning about configuring Vulnerability scanning using Microsoft AZ-500 online course and Practice Exam Now!","og_url":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/","og_site_name":"Testprep Training Tutorials","article_modified_time":"2022-04-16T04:49:43+00:00","og_image":[{"url":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/08\/AZ_500-practice-tests-11.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/","url":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/","name":"Configuring Vulnerability scanning | Microsoft Azure AZ-500 Tutorials","isPartOf":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website"},"datePublished":"2020-08-21T05:50:29+00:00","dateModified":"2022-04-16T04:49:43+00:00","description":"Enhance your skills by learning about configuring Vulnerability scanning using Microsoft AZ-500 online course and Practice Exam Now!","breadcrumb":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/configuring-vulnerability-scanning\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.testpreptraining.ai\/tutorial\/"},{"@type":"ListItem","position":2,"name":"Configuring Vulnerability scanning"}]},{"@type":"WebSite","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#website","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","name":"Testprep Training Tutorials","description":"","publisher":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.testpreptraining.ai\/tutorial\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#organization","name":"Testprep Training","url":"https:\/\/www.testpreptraining.ai\/tutorial\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/","url":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","contentUrl":"https:\/\/www.testpreptraining.com\/tutorial\/wp-content\/uploads\/2020\/07\/tpt-logo-6.png","width":583,"height":153,"caption":"Testprep Training"},"image":{"@id":"https:\/\/www.testpreptraining.ai\/tutorial\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/17277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/comments?post=17277"}],"version-history":[{"count":4,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/17277\/revisions"}],"predecessor-version":[{"id":54641,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/pages\/17277\/revisions\/54641"}],"wp:attachment":[{"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/media?parent=17277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/categories?post=17277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/tutorial\/wp-json\/wp\/v2\/tags?post=17277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}