CompTIA Security+ (SY0-701)Security OperationsMedium

A vulnerability management team supports thousands of laptops that frequently connect from home networks, hotel Wi-Fi, and coffee shops, rarely joining the corporate network directly. The team needs continuous, up-to-date vulnerability data regardless of the laptops' network location. Which scanning approach best meets this need?

  1. ANon-credentialed port scanning
  2. BAgent-based scanning
  3. CUnauthenticated network-based scanning
  4. DPassive network scanning
Show answer & explanation

Correct answer: B. Agent-based scanning

Agent-based scanning installs lightweight software on each endpoint that reports vulnerability data over the internet regardless of network location, making it ideal for remote or intermittently connected devices. Network-based and passive scans require the device to be reachable on a monitored network segment.

Why the other options are wrong

  • A. Non-credentialed port scans also require network reachability and give limited detail.
  • C. Unauthenticated network scans require the device to be on a reachable network.
  • D. Passive scanning monitors network traffic and requires the device on the monitored segment.

Agent-Based Vulnerability Scanning

A scanning method where software agents are installed on endpoints to collect vulnerability data locally and report it to a central console, independent of network location.

  • Ideal for remote/roaming devices
  • Provides continuous local visibility
  • Requires agent deployment and maintenance overhead

Memory trick: An agent travels with the laptop like a bodyguard, reporting home from anywhere.

More Security Operations questions