CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A vulnerability management team runs a scan against a fleet of Windows servers using SCAP content mapped to the CIS Benchmark for Windows Server 2019. The scan checks registry values, password policy settings, and audit configurations rather than searching for unpatched CVEs. Which type of scan is being performed?
- AConfiguration compliance scan
- BDynamic application scan
- CPenetration test
- DNetwork discovery scan
Show answer & explanationAnswer & explanation
Correct answer: A. Configuration compliance scan
A configuration compliance scan evaluates a system's settings against a security baseline or benchmark (such as CIS) to verify hardening standards are met, distinct from vulnerability scans that look for known CVEs.
Why the other options are wrong
- B. A dynamic application scan (DAST) tests running web applications for exploitable flaws, not OS configuration.
- C. A penetration test involves active exploitation attempts by a human tester, not automated policy checks.
- D. A network discovery scan identifies live hosts and open ports, not policy settings.
Configuration Compliance Scanning
A scan type that checks system settings against a security baseline (e.g., CIS Benchmarks, DISA STIGs) using standards like SCAP, rather than searching for software vulnerabilities.
- Validates hardening settings: passwords, auditing, registry keys
- Often automated via SCAP-compliant tools
- Complements, but differs from, CVE-based vulnerability scanning
Memory trick: Compliance checks the rulebook, not the CVE list.