Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementHard

A security team is considering using a vulnerability scanner that requires network access to the target systems but does not need any authentication credentials for those systems. What limitation should the team be aware of regarding the depth of analysis provided by this type of scan?

  1. AIt can identify vulnerabilities requiring authenticated access for exploitation.
  2. BIt primarily identifies network-level vulnerabilities and open ports.
  3. CIt provides a comprehensive view of internal system vulnerabilities.
  4. DIt can accurately detect missing patches and misconfigurations.
Show answer & explanation

Correct answer: B. It primarily identifies network-level vulnerabilities and open ports.

An uncredentialed scan operates without authentication, simulating an external attacker's view. While it can find many vulnerabilities, its primary limitation is an inability to inspect internal system configurations, patch levels, or file permissions. Thus, it mainly detects network-level issues and identifies open services/ports visible externally.

Why the other options are wrong

  • A. Vulnerabilities requiring authenticated access for exploitation are typically missed by uncredentialed scans.
  • C. A comprehensive view of *internal* vulnerabilities requires authenticated access, which an uncredentialed scan lacks.
  • D. Without credentials, it's difficult for a scanner to accurately detect missing patches or internal misconfigurations.

Uncredentialed Scan Limitations

Drawbacks of performing a vulnerability scan without providing authentication credentials to the target system.

  • Limited to network-level services and open ports.
  • Cannot inspect internal configurations, patch levels, or file permissions.
  • May miss many internal vulnerabilities, leading to an incomplete risk picture.

Memory trick: No keys, no entry, only what's visible from outside.

More Vulnerability Management questions