CompTIA Security+ (SY0-701)Security OperationsEasy

A vulnerability management team wants scan results to include missing patches, misconfigured registry settings, and outdated software versions with high accuracy and minimal false positives. Which scan type should they use?

  1. ACredentialed authenticated scan
  2. BNon-credentialed external scan
  3. CAgentless port scan
  4. DPassive network scan
Show answer & explanation

Correct answer: A. Credentialed authenticated scan

A credentialed authenticated scan logs into the host with valid credentials, allowing the scanner to inspect installed software, patch levels, and configuration settings directly, producing more accurate results than external or passive scans.

Why the other options are wrong

  • B. Non-credentialed scans only see externally visible services, missing internal configuration details.
  • C. Agentless port scans only identify open ports, not patch or configuration status.
  • D. Passive scanning only observes traffic and cannot inspect installed software.

Credentialed Vulnerability Scan

A vulnerability scan performed using valid login credentials to inspect the internal state of a system.

  • Provides deeper visibility than non-credentialed scans
  • Reduces false positives/negatives
  • Requires proper account permissions and secure credential storage

Memory trick: Credentials unlock the inside view.

More Security Operations questions