CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard

An uncredentialed vulnerability scan of a Windows server reports dozens of missing security patches, but the system administrator insists the server is fully patched via WSUS. What is the MOST likely cause of this discrepancy, and what should the tester do to obtain more reliable results?

  1. AThe scanner's plugin feed is outdated; update the plugins and rescan without credentials
  2. BThe scan used an overly aggressive timing template; lower the timing template and rescan
  3. CA host-based firewall blocked scan traffic; disable the firewall before rescanning
  4. DThe scan relied on service banners and version fingerprinting rather than verified patch levels; perform a credentialed scan instead
Show answer & explanation

Correct answer: D. The scan relied on service banners and version fingerprinting rather than verified patch levels; perform a credentialed scan instead

Uncredentialed scans typically infer patch status from externally visible banners and version strings, which can be inaccurate if the vendor does not update version identifiers after patching. A credentialed scan authenticates to the host and directly inspects installed patches/registry keys, yielding far more accurate results and fewer false positives.

Why the other options are wrong

  • A. Outdated plugins can cause issues, but this doesn't address the fundamental limitation of uncredentialed banner-based detection.
  • B. Timing templates affect scan speed/accuracy of responses, not the fundamental patch-detection methodology.
  • C. A blocked firewall would typically cause missed findings or scan failures, not false 'missing patch' reports.

Credentialed vs. Uncredentialed Scanning

Uncredentialed scans infer vulnerabilities externally via banners/responses, while credentialed scans authenticate to the host to directly verify installed software, patches, and configurations, reducing false positives/negatives.

  • Credentialed scans use local admin/SSH/WinRM credentials
  • Reduces false positives from inaccurate version banners
  • Provides deeper visibility into local misconfigurations

Memory trick: Uncredentialed guesses from outside; Credentialed logs in and checks directly

More Vulnerability Discovery and Analysis questions