CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy

A security team needs to build an inventory of devices on a fragile industrial control network segment. Management is concerned that active port scanning could crash sensitive PLCs. Which asset discovery method should the analyst use?

  1. ARun an aggressive Nmap SYN scan against the entire subnet
  2. BDeploy a network tap or SPAN port to passively capture and analyze traffic
  3. CPerform a credentialed scan authenticating to each device
  4. DInstall vulnerability scanning agents on each PLC
Show answer & explanation

Correct answer: B. Deploy a network tap or SPAN port to passively capture and analyze traffic

Passive discovery observes existing network traffic without sending probe packets, making it safe for fragile OT/ICS devices that may not tolerate active scanning.

Why the other options are wrong

  • A. Active scanning sends packets that can crash sensitive or legacy devices.
  • C. Credentialed scanning still requires active network probes and authentication attempts.
  • D. Agent installation on legacy PLCs is often unsupported and risky.

Passive Asset Discovery

Identifying hosts and services by observing existing network traffic (e.g., via a tap or SPAN port) rather than sending probes.

  • Non-intrusive, safe for fragile/OT devices
  • Uses tools like Wireshark, Zeek, or NetFlow analysis
  • May miss idle devices that generate no traffic

Memory trick: Passive peeks, Active pokes.

More Vulnerability Management questions