Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A security team is considering implementing a continuous vulnerability scanning solution. Which of the following is the PRIMARY benefit of continuous scanning compared to periodic, scheduled scans?

  1. AEarlier detection of newly introduced vulnerabilities.
  2. BReduced false positives in scan reports.
  3. CLower overall cost of vulnerability management.
  4. DMore comprehensive coverage of all network assets.
Show answer & explanation

Correct answer: A. Earlier detection of newly introduced vulnerabilities.

Continuous scanning provides near real-time visibility into the security posture, allowing for the much faster detection of new vulnerabilities introduced by changes in the environment, new software deployments, or newly discovered CVEs. While it might contribute to comprehensive coverage over time (D), its primary advantage over periodic scans is timeliness. It doesn't inherently reduce false positives (A) or guarantee lower cost (B), which depends on implementation.

Why the other options are wrong

  • B. Continuous scanning does not inherently reduce false positives; that depends on the scanner's quality and configuration.
  • C. Continuous scanning often involves more resources and can be more expensive, not necessarily lower cost.
  • D. While continuous scanning aids in comprehensive coverage, the primary benefit over *periodic* scans is the speed of detection, not just coverage.

Continuous Vulnerability Scanning

An automated process of regularly and frequently scanning an organization's IT assets for security vulnerabilities, often integrated into CI/CD pipelines and operational workflows.

  • Provides near real-time security posture visibility.
  • Reduces the window of exposure to new vulnerabilities.
  • Supports 'shift-left' security by integrating into development stages.

Memory trick: Continuous is always watching, periodic is checking the clock.

More Vulnerability Management questions