Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementMedium

A large enterprise is evaluating multiple vulnerability scanning tools. One tool offers both agent-based and agentless scanning capabilities. The enterprise has a highly dynamic cloud environment with frequently changing virtual machines and containers, and also a stable on-premises infrastructure. Which statement accurately describes the optimal use of these scanning capabilities for this enterprise?

  1. ABoth agent-based and agentless scanning are equally effective and interchangeable across both environments.
  2. BAgent-based scanning is only suitable for endpoints, not servers, regardless of the environment.
  3. CAgent-based scanning is best for the stable on-premises infrastructure, while agentless is ideal for the dynamic cloud environment.
  4. DAgentless scanning is best for the stable on-premises infrastructure, while agent-based is ideal for the dynamic cloud environment.
Show answer & explanation

Correct answer: D. Agentless scanning is best for the stable on-premises infrastructure, while agent-based is ideal for the dynamic cloud environment.

Agent-based scanning is well-suited for dynamic environments like cloud VMs and containers because the agent can continuously monitor and report regardless of IP changes or ephemeral nature. Agentless scanning is often preferred for stable on-premises infrastructure as it avoids agent deployment overhead and can scan a broader range of devices from a central point, though it might perform less granular checks.

Why the other options are wrong

  • A. They are not equally effective or interchangeable; each has distinct advantages and disadvantages.
  • B. Agent-based scanning is effective for servers as well, providing deeper insights.
  • C. This swaps the optimal use cases; agentless is better for stable, agent-based for dynamic.

Agent-based vs. Agentless Scanning

Two primary methods of vulnerability scanning: agent-based installs a lightweight program on each target, while agentless scans targets remotely without local software installation.

  • Agent-based: continuous, deep insights, good for dynamic assets.
  • Agentless: less overhead, broader reach, good for stable assets.
  • Choice depends on environment, asset type, and monitoring needs.

Memory trick: Agent inside, or scan from outside.

More Vulnerability Management questions