CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy
A security team needs to build an inventory of devices on a fragile industrial control network segment. Management is concerned that active port scanning could crash sensitive PLCs. Which asset discovery method should the analyst use?
- ARun an aggressive Nmap SYN scan against the entire subnet
- BDeploy a network tap or SPAN port to passively capture and analyze traffic
- CPerform a credentialed scan authenticating to each device
- DInstall vulnerability scanning agents on each PLC
Show answer & explanationAnswer & explanation
Correct answer: B. Deploy a network tap or SPAN port to passively capture and analyze traffic
Passive discovery observes existing network traffic without sending probe packets, making it safe for fragile OT/ICS devices that may not tolerate active scanning.
Why the other options are wrong
- A. Active scanning sends packets that can crash sensitive or legacy devices.
- C. Credentialed scanning still requires active network probes and authentication attempts.
- D. Agent installation on legacy PLCs is often unsupported and risky.
Passive Asset Discovery
Identifying hosts and services by observing existing network traffic (e.g., via a tap or SPAN port) rather than sending probes.
- Non-intrusive, safe for fragile/OT devices
- Uses tools like Wireshark, Zeek, or NetFlow analysis
- May miss idle devices that generate no traffic
Memory trick: Passive peeks, Active pokes.