CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy
A company manages a large fleet of remote laptops that connect to the corporate VPN for only a few hours per week and are frequently offline. Which vulnerability scanning approach would provide the most consistent and up-to-date scan coverage for these devices?
- ANon-credentialed external scanning of the corporate VPN gateway
- BNetwork-based scanning launched from an on-premises scanner appliance
- CAgent-based scanning with software installed locally on each laptop
- DPassive network sniffing at the internet perimeter
Show answer & explanationAnswer & explanation
Correct answer: C. Agent-based scanning with software installed locally on each laptop
Agent-based scanners run locally on the endpoint and can scan and report whenever the device is powered on, regardless of network connectivity, making them ideal for intermittently connected remote hosts. Network-based and passive methods require the device to be reachable on the network at scan time.
Why the other options are wrong
- A. Only scans the VPN gateway itself, not the endpoints behind it.
- B. Requires the laptop to be online and reachable during the scan window, which is unreliable here.
- D. Passive sniffing only sees traffic when the device is actively communicating on the monitored segment.
Agent-Based Scanning
A vulnerability scanning model where lightweight software agents installed on each host perform local assessment and report findings back to a central console, independent of network location.
- Works well for remote, mobile, or intermittently connected devices
- Provides continuous local visibility without needing network reachability
- Consumes host resources but avoids network scan traffic and firewall issues
Memory trick: Agent goes wherever the laptop goes.