Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementEasy
A security team is conducting a vulnerability assessment on a publicly accessible web server. They are using an automated scanner configured to not use any authentication credentials, mimicking an unauthenticated external attacker. What type of scan is being performed in terms of authentication context?
- AUncredentialed scan
- BInternal scan
- CAuthenticated scan
- DCredentialed scan
Show answer & explanationAnswer & explanation
Correct answer: A. Uncredentialed scan
An uncredentialed scan (or unauthenticated scan) is performed without providing any login credentials to the target system. This simulates an attacker with no authorized access, focusing on externally exploitable vulnerabilities.
Why the other options are wrong
- B. Internal scan refers to the network location from which the scan is launched, not the authentication context.
- C. Authenticated scan means the scanner uses valid credentials to log into the system, which is opposite to the scenario.
- D. Credentialed scan is synonymous with authenticated scan, where the scanner logs into the target system.
Uncredentialed Scan
A vulnerability scan performed without providing any authentication credentials to the target system, simulating an unauthenticated attacker.
- Identifies externally exploitable vulnerabilities.
- Mimics an attacker with no prior access.
- Less thorough than a credentialed scan for internal flaws.
Memory trick: Credentials: Yes or No.