Active security monitoring
The opposite of passive security monitoring is active security monitoring. Active security monitoring is all about interrogating the environment to reveal security-related issues or incidents. Think, for example, of a vulnerability scanner that will systematically probe a target system for known vulnerabilities or misconfiguration of its services. Active security monitoring activities tend to reveal more incidents and are quicker than passive activities, with the compromise that they add a burden onto network and endpoint resources.
Active security monitoring will be explained in detail in Chapter 7, Active Security Monitoring.